A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by authenticated user with admin privileges to manipulate shipment settings to execute arbitrary code.
                
            References
                    | Link | Resource | 
|---|---|
| https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13 | Vendor Advisory | 
| https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2019-08-02 22:15
Updated : 2024-11-21 04:48
NVD link : CVE-2019-7923
Mitre link : CVE-2019-7923
CVE.ORG link : CVE-2019-7923
JSON object : View
Products Affected
                magento
- magento
CWE
                
                    
                        
                        CWE-918
                        
            Server-Side Request Forgery (SSRF)
