← back
CVE-2019-8156

CVE-2019-8156

EPSS 1.7%
A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to modify store configurations can manipulate the connector api endpoint to enable remote code execution.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →