Looking for the vulnerability index of Invicti's legacy products?
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-7888) - Vulnerability Database

Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-7888)

Description

An information disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to create email templates could leak sensitive data via a malicious email template.

References

Related Vulnerabilities