← Back to CVE List

CVE-2019-7139

Published: 2019-04-10T18:29Z
Last Modified: 2024-11-21T04:47Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt