CVE-2019-7852: Magento

Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.

A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Requests for a specific file path could result in a redirect to the URL of the Magento admin panel, disclosing its location to potentially unauthorized parties.

Affected products

  • Magento Magento: from 2.1.0, before 2.1.18 (fixed in 2.1.18); from 2.2.0, before 2.2.9 (fixed in 2.2.9); from 2.3.0, before 2.3.2 (fixed in 2.3.2)

Published 2019-08-02. Last modified 2026-06-17.