« Volver al listado

CVE-2019-8137

Estado: ModificadaAlta (8.8)—

A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to manipulate CMS section of the website can trigger remote code execution via custom layout update.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-8137",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "Adobe Systems Incorporated",
          "product": "Magento 2",
          "versions": [
            {
              "status": "affected",
              "version": "Magento 2.2 prior to 2.2.10"
            },
            {
              "status": "affected",
              "version": "Magento 2.3 prior to 2.3.3 or 2.3.2-p1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-11-06T00:15:11.077",
  "references": [
    {
      "url": "https://magento.com/security/patches/magento-2.3.3-and-2.2.10-security-update",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://magento.com/security/patches/magento-2.3.3-and-2.2.10-security-update",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to manipulate CMS section of the website can trigger remote code execution via custom layout update."
    },
    {
      "lang": "es",
      "value": "existe  una vulnerabilidad de ejecución de código remota en Magento versiones 2.2 anteriores a 2.2.10, Magento versiones 2.3 anteriores a 2.3.3 o 2.3.2-p1. Un usuario autenticado con privilegios para manipular la sección CMS del sitio web puede activar una ejecución de código remota por medio de una actualización de diseño personalizada."
    }
  ],
  "lastModified": "2026-06-17T02:41:33.193",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24318637-C95B-4811-87F5-14A6F4EDE2EC",
              "versionEndExcluding": "2.2.10",
              "versionStartIncluding": "2.2.0"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A06CF88F-F067-4058-9306-864FEA3D7062",
              "versionEndExcluding": "2.2.10",
              "versionStartIncluding": "2.2.0"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B720D2FA-A6FD-49A3-8B78-07993560081D",
              "versionEndExcluding": "2.3.2",
              "versionStartIncluding": "2.3.0"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B8C5A27-2957-4373-B0FE-8C7585B4B04E",
              "versionEndExcluding": "2.3.2",
              "versionStartIncluding": "2.3.0"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.3.2:-:*:*:commerce:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED7EB5B4-33F4-4389-BCA4-50A113F8C719"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.3.2:-:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "465133F9-0BFE-491E-8FE8-A263F9E2FC1D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@adobe.com"
}