Security Advisory
CVE-2019-8143
6.5
MEDIUM
Vulnerability Description
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to email templates can send malicious SQL queries and obtain access to sensitive information stored in the database.
Published Date
November 6, 2019
Official Source
NIST NVD Advisory