{ "schema_version": "1.4.0", "id": "GHSA-vfgg-4hvr-6rq9", "modified": "2022-05-24T17:00:29Z", "published": "2022-05-24T17:00:29Z", "aliases": [ "CVE-2019-8155" ], "details": "Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to perform unauthorized actions.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-8155" }, { "type": "WEB", "url": "https://magento.com/security/patches/supee-11219" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-11-06T00:15:00Z" } }