CVE-2019-7912Unrestricted File Upload in Magento

Severity
7.2HIGHNVD
EPSS
0.3%
top 43.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 2
Latest updateMay 24

Description

A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with admin privileges to edit configuration keys to remove file extension filters, potentially resulting in the malicious upload and execution of malicious files on the server.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages3 packages

Packagistmagento/community-edition2.12.1.18+2
NVDmagento/magento2.1.02.1.18+2
CVEListV5adobe_systems_incorporated/magento_2Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2

🔴Vulnerability Details

3
GHSA
Magento Filter extension bypass via crafted store configuration keys2022-05-24
OSV
Magento Filter extension bypass via crafted store configuration keys2022-05-24
CVEList
CVE-2019-7912: A file upload filter bypass exists in Magento 22019-08-02
CVE-2019-7912 — Unrestricted File Upload in Magento | cvebase