PT-2019-18832 · Adobe · Magento

Published

2019-08-02

·

Updated

2022-05-24

·

CVE-2019-7930

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Magento 2.1 versions 2.1.0 through 2.1.17 Magento 2.2 versions 2.2.0 through 2.2.8 Magento 2.3 versions 2.3.0 through 2.3.1
Description A file upload restriction bypass issue exists, allowing an authenticated user with administrator privileges to the import feature to modify a configuration file. This can lead to unauthorized removal of file upload restrictions, potentially resulting in arbitrary code execution when a malicious file is uploaded and executed on the system.
Recommendations For Magento 2.1 versions 2.1.0 through 2.1.17, update to version 2.1.18 or later. For Magento 2.2 versions 2.2.0 through 2.2.8, update to version 2.2.9 or later. For Magento 2.3 versions 2.3.0 through 2.3.1, update to version 2.3.2 or later.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-7930
GHSA-3H69-4FRW-G2JM

Affected Products

Magento