{"id":"CVE-2019-8230","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-8230","summary":"Magento Remote code execution through support/output path modification","details":"In Magento Open Source prior to 1.9.4.3, and Magento Commerce prior to 1.14.4.3, an authenticated user with administrative privileges to edit configuration settings can execute arbitrary code through a crafted support/output path.","published":"2022-05-24T17:00:29Z","modified":"2024-01-10T21:56:42.852834Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01412,"percentile":0.70247,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"magento/core","fixedVersion":"1.9.4.3"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-8230"},{"type":"WEB","url":"https://magento.com/security/patches/supee-11219"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-01-10T21:56:42.852834Z"}}