Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2019-7930

около 7 лет назад

A file upload restriction bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with administrator privileges to the import feature can make modifications to a configuration file, resulting in potentially unauthorized removal of file upload restrictions. This can result in arbitrary code execution when a malicious file is then uploaded and executed on the system.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3h69-4frw-g2jm

около 4 лет назад

Magento 2 Community Unrestricted File Upload

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-7930

A file upload restriction bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with administrator privileges to the import feature can make modifications to a configuration file, resulting in potentially unauthorized removal of file upload restrictions. This can result in arbitrary code execution when a malicious file is then uploaded and executed on the system.

CVSS3: 7.2
2%
Низкий
около 7 лет назад
github логотип
GHSA-3h69-4frw-g2jm

Magento 2 Community Unrestricted File Upload

CVSS3: 7.2
2%
Низкий
около 4 лет назад

Уязвимостей на страницу