CVE-2019-8144 is a critical remote code execution (RCE) vulnerability affecting Magento 2.3 prior to versions 2.3.3 or 2.3.2-p1. An unauthenticated attacker can exploit this flaw by injecting malicious payloads via PageBuilder template methods. With a CVSS score of 9.8, this vulnerability allows for complete compromise of confidentiality, integrity, and availability with low attack complexity and no user interaction required. While there are no known public exploits in Metasploit or ExploitDB, the vulnerability has garnered significant media attention and community discussion, indicating its potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3.0, < 2.3.2CPE matchmatch criteria | cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* | ||
>= 2.3.0, < 2.3.2CPE matchmatch criteria | cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* | ||
2.3.2CPE matchmatch criteria | cpe:2.3:a:magento:magento:2.3.2:-:*:*:commerce:*:*:* | ||
2.3.2CPE matchmatch criteria | cpe:2.3:a:magento:magento:2.3.2:-:*:*:open_source:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.