Security Advisory

CVE-2019-8232

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-11-05 23:55:43
Last updated 2024-08-04 21:10:33
Assigner adobe
CVSS score not scored
State PUBLISHED

Description

In Magento prior to 1.9.4.3, Magento prior to 1.14.4.3, Magento 2.2 prior to 2.2.10, and Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an authenticated user with administrative privileges for the import feature can execute arbitrary code through a race condition that allows webserver configuration file modification.