GHSA-r728-jwf5-f5r5
Dashboard / Vulnerabilities / GHSA-r728-jwf5-f5r5
Summary: Magento Reflected cross-site scripting on customer cart page
Details: A reflected cross-site scripting vulnerability exists on the customer cart checkout page of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by sending a victim a crafted URL that results in malicious javascript execution in the victim's browser.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-7939, https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2019-7939.yaml, https://github.com/magento/magento2, https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-23
Affected packages
Package
Name: magento/community-edition
Purl: pkg:composer/magento/community-edition
Affected ranges
Type: ECOSYSTEM
Events:
