CVE Published: 05/11/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: adobe |
Vendor: Adobe Systems Incorporated |
Product: Magento 1 Status : PUBLISHED
CVE-2019-8155 Description
Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user\'s CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to perform unauthorized actions.