VYPR
Medium severity4.9NVD Advisory· Published Nov 5, 2019· Updated Jun 17, 2026

CVE-2019-8126

CVE-2019-8126

Description

An XML entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can craft document type definition for an XML representing XML layout. The crafted document type definition and XML layout allow processing of external entities which can lead to information disclosure.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
magento/community-editionPackagist
>= 2.2, < 2.2.102.2.10
magento/community-editionPackagist
>= 2.3, < 2.3.2-p22.3.2-p2

Affected products

6
  • Magento/Magento4 versions
    cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*+ 3 more
    • cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*range: >=2.2.0,<2.2.10
    • cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*range: >=2.2.0,<2.2.10
    • cpe:2.3:a:magento:magento:2.3.2:-:*:*:commerce:*:*:*
    • cpe:2.3:a:magento:magento:2.3.2:-:*:*:open_source:*:*:*
  • ghsa-coords
    Range: >= 2.2, < 2.2.10
  • Range: Magento 2.2 prior to 2.2.10

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.