SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-7882

A stored cross-site scripting vulnerability exists in the WYSIWYG editor of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

MEDIUM 5.4EPSS 0.57%

Does this matter?

Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.

Description

A stored cross-site scripting vulnerability exists in the WYSIWYG editor of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to the editor can inject malicious SWF files.

CVSS 3.0
5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.57% probability · 45th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
magento/magento
Source
psirt@adobe.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.