An information disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to create email templates could leak sensitive data via a malicious email template.
References
Link | Resource |
---|---|
https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-33 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2019-08-02 22:15
Updated : 2021-07-21 11:39
NVD link : CVE-2019-7888
Mitre link : CVE-2019-7888
CVE.ORG link : CVE-2019-7888
JSON object : View
Products Affected
magento
- magento
CWE