#VU22323 Information disclosure in Adobe Commerce (formerly Magento Commerce) - CVE-2019-7888
Published: October 29, 2019
Adobe Commerce (formerly Magento Commerce)
Adobe
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to improper input validation in the email template. A remote authenticated attacker with privileges to create email templates can gain unauthorized access to sensitive information on the system via a malicious email template.