{"id":"CVE-2019-8231","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-8231","summary":"Magento Remote code execution through catalog attribute sets","details":"In Magento Open Source prior to 1.9.4.3, and Magento Commerce prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layout modification.","published":"2022-05-24T17:00:30Z","modified":"2024-01-10T21:56:42.918641Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"magento/core","fixedVersion":"1.9.4.3"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-8231"},{"type":"WEB","url":"https://magento.com/security/patches/supee-11219"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-01-10T21:56:42.918641Z"}}