Логотип exploitDog
bind:CVE-2019-7912
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-7912

Количество 2

Количество 2

nvd логотип

CVE-2019-7912

больше 6 лет назад

A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with admin privileges to edit configuration keys to remove file extension filters, potentially resulting in the malicious upload and execution of malicious files on the server.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-f8h9-7rpq-7qcc

больше 3 лет назад

Magento Filter extension bypass via crafted store configuration keys

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-7912

A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with admin privileges to edit configuration keys to remove file extension filters, potentially resulting in the malicious upload and execution of malicious files on the server.

CVSS3: 7.2
0%
Низкий
больше 6 лет назад
github логотип
GHSA-f8h9-7rpq-7qcc

Magento Filter extension bypass via crafted store configuration keys

CVSS3: 7.2
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу