A security bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 that could be abused to execute arbitrary PHP code. An authenticated user can bypass security protections that prevent arbitrary PHP script upload via form data injection.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published: 2019-08-02T21:17:01

Updated: 2024-08-04T21:02:18.955Z

Reserved: 2019-02-12T00:00:00

Link: CVE-2019-7871

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-08-02T22:15:15.877

Modified: 2020-08-24T17:37:01.140

Link: CVE-2019-7871

cve-icon Redhat

No data.