Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2019-7888 - Vulnerability Database

Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2019-7888

Medium
Reference: CVE-2019-7888
Title: Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Overview:

An information disclosure vulnerability exists in Magento 2.1 prior to 2.1.18 Magento 2.2 prior to 2.2.9 Magento 2.3 prior to 2.3.2. An authenticated user with privileges to create email templates could leak sensitive data via a malicious email template.