Information disclosure in Magento Open Source - #VU18712

 

Information disclosure in Magento Open Source - #VU18712

Published: June 7, 2019


Vulnerability identifier: #VU18712
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to NGINX configuration's regular expressions not being restricted to the explicit directories. A remote administrator can upload PHP files to access sensitive data, because NGINX configuration allows PHP files to be executed in any directory.


Affected software

Magento Open Source

Remediation

Install updates from vendor's website.

Magento Open Source - update to 2.1.17

External References

Related Security Bulletins