CVE-2019-7139

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
10/04/2019
Last modified:
06/08/2019

Description

An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* 1.9.4.1 (excluding)
cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* 1.14.0.0 (including) 1.14.4.1 (excluding)
cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* 2.1.0 (including) 2.1.17 (excluding)
cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* 2.1.0 (including) 2.1.17 (excluding)
cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* 2.2.0 (including) 2.2.8 (excluding)
cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* 2.2.0 (including) 2.2.8 (excluding)
cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* 2.3.0 (including) 2.3.1 (excluding)
cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* 2.3.0 (including) 2.3.1 (excluding)