← back
CVE-2019-8132

CVE-2019-8132

EPSS 0.6%
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft malicious payload in the template Name field for Email template in the "Design Configuration" dashboard.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →