Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal vulnerability in Magento UPWARD Connector version 1.1.2 (and earlier) due to the upload feature. An attacker could potentially exploit this vulnerability to upload a malicious YAML file that can contain instructions which allows reading arbitrary files from the remote server. Access to the admin console is required for successful exploitation.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-8455 Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal vulnerability in Magento UPWARD Connector version 1.1.2 (and earlier) due to the upload feature. An attacker could potentially exploit this vulnerability to upload a malicious YAML file that can contain instructions which allows reading arbitrary files from the remote server. Access to the admin console is required for successful exploitation.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2024-09-16T16:12:26.679Z

Reserved: 2020-12-18T00:00:00

Link: CVE-2021-21064

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-02-25T14:15:12.143

Modified: 2024-11-21T05:47:29.927

Link: CVE-2021-21064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.