ZeroHour

CVE-2019-7861

CVSS 3.0
7.5 high
EPSS
2%p80
Published
()
Modified
Description

Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

Vendors
magento
Products
magento
Ecosystems
E-commerce
Weakness
CWE-434
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.