Code Injection in Magento Open Source and Adobe Commerce (formerly Magento Commerce) - CVE-2019-8114

 

Code Injection in Magento Open Source and Adobe Commerce (formerly Magento Commerce) - CVE-2019-8114

Published: November 13, 2019


Vulnerability identifier: #VU22749
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-8114
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation. A remote administrator with privileges to import features can execute arbitrary code through a crafted configuration archive file upload.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Magento Open Source
Adobe Commerce (formerly Magento Commerce)

How to mitigate CVE-2019-8114

Install update from vendor's website.

Magento Open Source - update to 1.9.4.3
Adobe Commerce (formerly Magento Commerce) - addressed in versions 1.14.4.3, 2.2.10, 2.3.2-p1, 2.3.3

External References

Related Security Bulletins