CVE-2019-7861Unrestricted File Upload in Magento

Severity
7.5HIGHNVD
EPSS
0.1%
top 81.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 2
Latest updateMay 24

Description

Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDmagento/magento2.1.02.1.18+2
Packagistmagento/community-edition2.1.02.1.18+2
CVEListV5adobe_systems_incorporated/magento_2Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2

🔴Vulnerability Details

3
OSV
Magento 2 Community Edition Unsafe File Upload2022-05-24
GHSA
Magento 2 Community Edition Unsafe File Upload2022-05-24
CVEList
CVE-2019-7861: Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 22019-08-02
CVE-2019-7861 — Unrestricted File Upload in Magento | cvebase