« Volver al listado

CVE-2019-8110

Estado: ModificadaAlta (8.8)—

A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage email templates hierarchy to manipulate the interceptor class in a way that allows an attacker to execute arbitrary code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-8110",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "Adobe Systems Incorporated",
          "product": "Magento 2",
          "versions": [
            {
              "status": "affected",
              "version": "Magento 2.2 prior to 2.2.10"
            },
            {
              "status": "affected",
              "version": "Magento 2.3 prior to 2.3.3 or 2.3.2-p1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-11-05T23:15:11.790",
  "references": [
    {
      "url": "https://magento.com/security/patches/magento-2.3.3-and-2.2.10-security-update",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://magento.com/security/patches/magento-2.3.3-and-2.2.10-security-update",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage email templates hierarchy to manipulate the interceptor class in a way that allows an attacker to execute arbitrary code."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad de ejecución de código remota en Magento versiones 2.2 anteriores a 2.2.10, Magento versiones 2.3 anteriores a 2.3.3 o 2.3.2-p1. Un usuario autenticado puede aprovechar la jerarquía de las plantillas de correo electrónico para manipular la clase interceptor de una manera que permita a un atacante ejecutar código arbitrario."
    }
  ],
  "lastModified": "2026-06-17T02:41:30.530",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24318637-C95B-4811-87F5-14A6F4EDE2EC",
              "versionEndExcluding": "2.2.10",
              "versionStartIncluding": "2.2.0"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A06CF88F-F067-4058-9306-864FEA3D7062",
              "versionEndExcluding": "2.2.10",
              "versionStartIncluding": "2.2.0"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B720D2FA-A6FD-49A3-8B78-07993560081D",
              "versionEndExcluding": "2.3.2",
              "versionStartIncluding": "2.3.0"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B8C5A27-2957-4373-B0FE-8C7585B4B04E",
              "versionEndExcluding": "2.3.2",
              "versionStartIncluding": "2.3.0"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.3.2:-:*:*:commerce:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED7EB5B4-33F4-4389-BCA4-50A113F8C719"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.3.2:-:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "465133F9-0BFE-491E-8FE8-A263F9E2FC1D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@adobe.com"
}