312
VMScore

CVE-2019-8228

Published: 06/11/2019 Updated: 07/11/2019
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

in Magento before 1.9.4.3 and Magento before 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code into transactional email page when creating a new email template or editing existing email template.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

magento magento