CVE-2019-8155
Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be e
Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to perform unauthorized actions.
HIGH · CVSS 7.5
EPSS 0.00065
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0