Magento Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2019-7139 - Vulnerability Database

Magento Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2019-7139

Critical
Reference: CVE-2019-7139
Title: Magento Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18 Magento 2.2 prior to 2.2.9 Magento 2.3 prior to 2.3.2.