CVE-2019-8155
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.5%
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
nono source reports it
Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to perform unauthorized actions.
Affected products
Adobe Systems Incorporated · Magento 1