An arbitrary file deletion vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated users can manipulate the design layout update feature.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2712 | An arbitrary file deletion vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated users can manipulate the design layout update feature. |
Github GHSA |
GHSA-653q-vqm6-gmjm | Magento 2 Community Edition Arbitrary File Deletion |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-08-04T21:10:32.544Z
Reserved: 2019-02-12T00:00:00
Link: CVE-2019-8090
No data.
Status : Modified
Published: 2019-11-05T22:15:14.080
Modified: 2024-11-21T04:49:15.970
Link: CVE-2019-8090
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA