Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This vulnerability could be abused by an authenticated user with the ability to configure the catalog search.
References
Link | Resource |
---|---|
https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2019-08-02 22:15
Updated : 2024-02-04 20:20
NVD link : CVE-2019-7885
Mitre link : CVE-2019-7885
CVE.ORG link : CVE-2019-7885
JSON object : View
Products Affected
magento
- magento
CWE
CWE-20
Improper Input Validation