← back
CVE-2019-7139observed exploitation

CVE-2019-7139

65Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 18%
from disclosure to weapon2295 days
Published on NVDApr 10
1st PoC+2295d
VulnCheckApr 2
exploitation probability
18%top 3% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.