← back
CVE-2019-8114

CVE-2019-8114

EPSS 1.9%
A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to import features can execute arbitrary code via crafted configuration archive file upload.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →