Security Advisory

CVE-2019-8143

6.5
MEDIUM

Vulnerability Description

A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to email templates can send malicious SQL queries and obtain access to sensitive information stored in the database.
Published Date November 6, 2019
Official Source NIST NVD Advisory