|
212081
|
8.8 |
HIGH
Network
|
magento
|
magento
|
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage plugin functionality related to email templates…
|
NVD-CWE-noinfo
|
CVE-2019-8111
|
2024-11-21 13:49 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212082
|
8.8 |
HIGH
Network
|
magento
|
magento
|
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage email templates hierarchy to manipulate the int…
|
NVD-CWE-noinfo
|
CVE-2019-8110
|
2024-11-21 13:49 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212083
|
8.0 |
HIGH
Network
|
magento
|
magento
|
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft a malicious CSRF payload that can result in arbitr…
|
CWE-352
Origin Validation Error
|
CVE-2019-8109
|
2024-11-21 13:49 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212084
|
6.5 |
MEDIUM
Network
|
magento
|
magento
|
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate session validation set…
|
CWE-287
Improper Authentication
|
CVE-2019-8108
|
2024-11-21 13:49 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212085
|
6.5 |
MEDIUM
Network
|
magento
|
magento
|
An arbitrary file deletion vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with export data transfer privileges can craft a request …
|
NVD-CWE-noinfo
|
CVE-2019-8107
|
2024-11-21 13:49 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212086
|
8.8 |
HIGH
Network
|
magento
|
magento
|
An arbitrary file access vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage file upload controller for downloadable produc…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-8093
|
2024-11-21 13:49 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212087
|
5.4 |
MEDIUM
Network
|
magento
|
magento
|
A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via emai…
|
CWE-79
Cross-site Scripting
|
CVE-2019-8092
|
2024-11-21 13:49 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212088
|
7.2 |
HIGH
Network
|
magento
|
magento
|
A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3. An authenticated admin user with privileges to access product attributes can leverage layout updates to trigge…
|
NVD-CWE-noinfo
|
CVE-2019-8091
|
2024-11-21 13:49 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212089
|
6.5 |
MEDIUM
Network
|
magento
|
magento
|
An arbitrary file deletion vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated users can manipulate the design layout update…
|
NVD-CWE-noinfo
|
CVE-2019-8090
|
2024-11-21 13:49 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212090
|
6.5 |
MEDIUM
Network
|
magento
|
magento
|
An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 prior to 2.2.8, and 2.1 prior to 2.1.17 versions. An authenticated user may be able to view personal…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-8235
|
2024-11-21 13:49 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|