A path traversal vulnerability in the WYSIWYG editor for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could result in unauthorized access to uploaded images due to insufficient access control.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published: 2019-08-02T21:13:08

Updated: 2024-08-04T21:02:18.966Z

Reserved: 2019-02-12T00:00:00

Link: CVE-2019-7859

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-08-02T22:15:15.173

Modified: 2019-08-06T18:30:44.370

Link: CVE-2019-7859

cve-icon Redhat

No data.