{"id":"CVE-2019-8231","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-8231","summary":"In Magento to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layout modification.","details":"In Magento to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layout modification.","published":"2019-11-05T23:56:33.000Z","modified":"2024-08-04T21:10:33.540Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://magento.com/security/patches/supee-11219"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2024-08-04T21:10:33.540Z"}}