Security Advisory
CVE-2019-8138
5.4
MEDIUM
Vulnerability Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can execute arbitrary JavaScript code by providing arbitrary API endpoint that will not be chcecked by sale pickup event.
Published Date
November 6, 2019
Official Source
NIST NVD Advisory