Description
An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rendering module that gets passed to XML data processing engine without validation. The crafted key/value GET request data allows an attacker to limited access to underlying XML data.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3208 | An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rendering module that gets passed to XML data processing engine without validation. The crafted key/value GET request data allows an attacker to limited access to underlying XML data. |
Github GHSA |
GHSA-8p5c-f836-m4h7 | Magento 2 Community Edition XML Injection |
References
History
No history.
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-08-04T21:10:33.504Z
Reserved: 2019-02-12T00:00:00.000Z
Link: CVE-2019-8158
No data.
Status : Modified
Published: 2019-11-06T01:15:25.433
Modified: 2024-11-21T04:49:23.623
Link: CVE-2019-8158
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA