An unrestricted file upload vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can manipulate the Synchronization feature in the Media File Storage of the database to transform uploaded JPEG file into a PHP file.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-3042 An unrestricted file upload vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can manipulate the Synchronization feature in the Media File Storage of the database to transform uploaded JPEG file into a PHP file.
Github GHSA Github GHSA GHSA-7pr3-34rg-g53m Magento Unrestricted file upload vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2024-08-04T21:10:32.997Z

Reserved: 2019-02-12T00:00:00

Link: CVE-2019-8140

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-06T00:15:11.343

Modified: 2024-11-21T04:49:21.620

Link: CVE-2019-8140

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses