CVE Vulnerabilities

CVE-2019-7932

Published: Aug 02, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A remote code execution vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with admin privileges to create sitemaps can execute arbitrary PHP code by creating a malicious sitemap file.

Affected Software

NameVendorStart VersionEnd Version
MagentoMagento*1.9.4.2 (excluding)
MagentoMagento*1.14.4.2 (excluding)
MagentoMagento2.1.0 (including)2.1.18 (excluding)
MagentoMagento2.2.0 (including)2.2.9 (excluding)
MagentoMagento2.3.0 (including)2.3.2 (excluding)

References