← back
CVE-2019-8143

CVE-2019-8143

EPSS 0.9%
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to email templates can send malicious SQL queries and obtain access to sensitive information stored in the database.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →