8.8
CVSSv3

CVE-2019-8110

CVSSv4: NA | CVSSv3: 8.8 | CVSSv2: 6.5 | VMScore: 980 | EPSS: 0.01125 | KEV: Not Included
Published: 05/11/2019 Updated: 21/11/2024

Vulnerability Summary

A remote code execution vulnerability exists in Magento 2.2 before 2.2.10, Magento 2.3 before 2.3.3 or 2.3.2-p1. An authenticated user can leverage email templates hierarchy to manipulate the interceptor class in a way that allows an malicious user to execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe systems incorporated magento 2

magento magento

magento magento 2.3.2