CVE Vulnerabilities

CVE-2019-8111

Published: Nov 05, 2019 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage plugin functionality related to email templates to manipulate the interceptor class in a way that allows an attacker to execute arbitrary code.

Affected Software

Name Vendor Start Version End Version
Magento Magento 2.2.0 (including) 2.2.10 (excluding)
Magento Magento 2.3.0 (including) 2.3.2 (excluding)
Magento Magento 2.3.2 (including) 2.3.2 (including)

References