CVE-2019-7912
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with admin privileges to edit configuration keys to remove file extension filters, potentially resulting in the malicious upload and execution of malicious files on the server.
Se presenta una omisión del filtro de carga de archivos en Magento versiones 2.1 anteriores a 2.1.18, Magento versiones 2.2 anteriores a 2.2.9, Magento versiones 2.3 anteriores a 2.3.2. Esto puede ser explotado por un usuario autenticado con privilegios de administrador para editar las claves de configuración para eliminar los filtros de extensión de archivo, resultando en la carga maliciosa y la ejecución de archivos maliciosos sobre el servidor.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-02-12 CVE Reserved
- 2019-08-02 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-33 | 2019-08-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | >= 2.1.0 < 2.1.18 Search vendor "Magento" for product "Magento" and version " >= 2.1.0 < 2.1.18" | open_source |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | >= 2.2.0 < 2.2.9 Search vendor "Magento" for product "Magento" and version " >= 2.2.0 < 2.2.9" | open_source |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | >= 2.3.0 < 2.3.2 Search vendor "Magento" for product "Magento" and version " >= 2.3.0 < 2.3.2" | open_source |
Affected
|