← back
CVE-2019-8157

CVE-2019-8157

EPSS 0.6%
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate downloadable link and cause an invocation of error handling that acceses user input without sanitization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →