CVE-2019-7888

EUVD-2022-3422
An information disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to create email templates could leak sensitive data via a malicious email template.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 29%
Affected Products (NVD)
VendorProductVersion
magentomagento
2.1.0 ≤
𝑥
< 2.1.18
magentomagento
2.2.0 ≤
𝑥
< 2.2.9
magentomagento
2.3.0 ≤
𝑥
< 2.3.2
𝑥
= Vulnerable software versions