GHSA-wmrg-w9vg-7jqx
Dashboard / Vulnerabilities / GHSA-wmrg-w9vg-7jqx
Summary: Magento 2 Community Edition CSRF Vulnerability
Details: A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited at the time of editing or configuration.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-7865, https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2019-7865.yaml, https://github.com/magento/magento2, https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-33, https://web.archive.org/web/20220121011306/https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-33
Affected packages
Package
Name: magento/community-edition
Purl: pkg:composer/magento/community-edition
Affected ranges
Type: ECOSYSTEM
Events:
