← back
CVE-2019-8138

CVE-2019-8138

EPSS 0.6%
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can execute arbitrary JavaScript code by providing arbitrary API endpoint that will not be chcecked by sale pickup event.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →