← All CVEs

CVE-2019-7139

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

9.8
CVSS
18.3%
EPSS (exploit prob.)
97th
EPSS percentile
2019-04-10
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

Affected products

VendorProductAffected versions
magentomagento< 1.9.4.1
magentomagento>= 1.14.0.0, < 1.14.4.1
magentomagento>= 2.1.0, < 2.1.17
magentomagento>= 2.1.0, < 2.1.17
magentomagento>= 2.2.0, < 2.2.8
magentomagento>= 2.2.0, < 2.2.8
magentomagento>= 2.3.0, < 2.3.1
magentomagento>= 2.3.0, < 2.3.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-7139