Security Advisory

CVE-2019-8138

5.4
MEDIUM

Vulnerability Description

A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can execute arbitrary JavaScript code by providing arbitrary API endpoint that will not be chcecked by sale pickup event.
Published Date November 6, 2019
Official Source NIST NVD Advisory