Vulnerability Description
An XML entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can craft document type definition for an XML representing XML layout. The crafted document type definition and XML layout allow processing of external entities which can lead to information disclosure.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Magento | Magento | >= 2.2.0, < 2.2.10 |
Related Weaknesses (CWE)
References
- https://magento.com/security/patches/magento-2.3.3-and-2.2.10-security-updatePatchVendor Advisory
- https://magento.com/security/patches/magento-2.3.3-and-2.2.10-security-updatePatchVendor Advisory
FAQ
What is CVE-2019-8126?
CVE-2019-8126 is a vulnerability with a CVSS score of 4.9 (MEDIUM). An XML entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can craft document type definition for an XML represent...
How severe is CVE-2019-8126?
CVE-2019-8126 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-8126?
Check the references section above for vendor advisories and patch information. Affected products include: Magento Magento.