A stored cross-site scripting (XSS) vulnerability exists in in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to the wysiwyg editor can abuse the blockDirective() function and inject malicious javascript in the cache of the admin dashboard.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4390 | A stored cross-site scripting (XSS) vulnerability exists in in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to the wysiwyg editor can abuse the blockDirective() function and inject malicious javascript in the cache of the admin dashboard. |
Github GHSA |
GHSA-jjmg-xmq2-g6ff | Magento 2 Community Edition XSS Vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://magento.com/security/patches/supee-11219 |
|
History
No history.
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-08-04T21:10:33.108Z
Reserved: 2019-02-12T00:00:00.000Z
Link: CVE-2019-8152
No data.
Status : Modified
Published: 2019-11-06T00:15:12.577
Modified: 2024-11-21T04:49:22.940
Link: CVE-2019-8152
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA