VDB
Sign up
MEDIUM4.8

GHSA-mgfr-44wv-hqv6

Magento 2 Community Edition XSS Vulnerability

Quick fix

GHSA-mgfr-44wv-hqv6 — magento/community-edition: upgrade to the fixed version with the command below.

composer require magento/community-edition:^2.1.18

Details

A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to modify catalog price rules to inject malicious javascript.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/magento/community-edition
Introduced in: 2.1.0Fixed in: 2.1.18
Fixcomposer require magento/community-edition:^2.1.18
Packagist/magento/community-edition
Introduced in: 2.2.0Fixed in: 2.2.9
Fixcomposer require magento/community-edition:^2.2.9
Packagist/magento/community-edition
Introduced in: 2.3.0Fixed in: 2.3.2
Fixcomposer require magento/community-edition:^2.3.2
Packagist/magento/magento1ce
Introduced in: 1Fixed in: 1.9.4.2
Fixcomposer require magento/magento1ce:^1.9.4.2
Packagist/magento/magento1ee
Introduced in: 1Fixed in: 1.14.4.2
Fixcomposer require magento/magento1ee:^1.14.4.2
Packagist/magento/product-community-edition
Introduced in: 2.1Fixed in: 2.1.18
Fixcomposer require magento/product-community-edition:^2.1.18
Packagist/magento/product-community-edition
Introduced in: 2.2Fixed in: 2.2.9
Fixcomposer require magento/product-community-edition:^2.2.9
Packagist/magento/product-community-edition
Introduced in: 2.3Fixed in: 2.3.2
Fixcomposer require magento/product-community-edition:^2.3.2

References