CVE-2019-7912
published 2019-08-02CVE-2019-7912: A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an…
PriorityP342high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
EPSS
1.58%
72.6th percentile
A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with admin privileges to edit configuration keys to remove file extension filters, potentially resulting in the malicious upload and execution of malicious files on the server.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| magento | community-edition | >= 2.1 < 2.1.18 | 2.1.18 |
| magento | community-edition | >= 2.2 < 2.2.9 | 2.2.9 |
| magento | community-edition | >= 2.3 < 2.3.2 | 2.3.2 |
| magento | magento | >= 2.1.0 < 2.1.18 | 2.1.18 |
| magento | magento | >= 2.2.0 < 2.2.9 | 2.2.9 |
| magento | magento | >= 2.3.0 < 2.3.2 | 2.3.2 |
CVSS provenance
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Magento Filter extension bypass via crafted store configuration keys
ghsa·2022-05-24
CVE-2019-7912 [HIGH] CWE-434 Magento Filter extension bypass via crafted store configuration keys
Magento Filter extension bypass via crafted store configuration keys
A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with admin privileges to edit configuration keys to remove file extension filters, potentially resulting in the malicious upload and execution of malicious files on the server.
OSV
Magento Filter extension bypass via crafted store configuration keys
osv·2022-05-24
CVE-2019-7912 [HIGH] Magento Filter extension bypass via crafted store configuration keys
Magento Filter extension bypass via crafted store configuration keys
A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with admin privileges to edit configuration keys to remove file extension filters, potentially resulting in the malicious upload and execution of malicious files on the server.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-08-02
Published