MEDIUM4.8
GHSA-mgfr-44wv-hqv6
Magento 2 Community Edition XSS Vulnerability
Quick fix
GHSA-mgfr-44wv-hqv6 — magento/community-edition: upgrade to the fixed version with the command below.
composer require magento/community-edition:^2.1.18Details
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to modify catalog price rules to inject malicious javascript.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/magento/community-edition
Introduced in:
2.1.0Fixed in: 2.1.18Fix
composer require magento/community-edition:^2.1.18Packagist/magento/community-edition
Introduced in:
2.2.0Fixed in: 2.2.9Fix
composer require magento/community-edition:^2.2.9Packagist/magento/community-edition
Introduced in:
2.3.0Fixed in: 2.3.2Fix
composer require magento/community-edition:^2.3.2Packagist/magento/magento1ce
Introduced in:
1Fixed in: 1.9.4.2Fix
composer require magento/magento1ce:^1.9.4.2Packagist/magento/magento1ee
Introduced in:
1Fixed in: 1.14.4.2Fix
composer require magento/magento1ee:^1.14.4.2Packagist/magento/product-community-edition
Introduced in:
2.1Fixed in: 2.1.18Fix
composer require magento/product-community-edition:^2.1.18Packagist/magento/product-community-edition
Introduced in:
2.2Fixed in: 2.2.9Fix
composer require magento/product-community-edition:^2.2.9Packagist/magento/product-community-edition
Introduced in:
2.3Fixed in: 2.3.2Fix
composer require magento/product-community-edition:^2.3.2References
- https://nvd.nist.gov/vuln/detail/CVE-2019-7938[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/magento1ce/CVE-2019-7938.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/magento1ee/CVE-2019-7938.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2019-7938.yaml[WEB]
- https://github.com/magento/magento2[PACKAGE]
- https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-23[WEB]
- https://web.archive.org/web/20220121051916/https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-23[WEB]