CVE-2019-8116
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can leverage a guest session id value following a successful login to gain access to customer account index page.
HIGH · CVSS 7.5
EPSS 0.00388
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0