Path traversal in Adobe Commerce (formerly Magento Commerce) - #VU8461

 

Path traversal in Adobe Commerce (formerly Magento Commerce) - #VU8461

Published: September 15, 2017


Vulnerability identifier: #VU8461
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to view contents of arbitrary files on the system.

The vulnerability exists due to insufficient input validation in theme creation function. A remote administrator with limited privileges can view or delete arbitrary files on the target system.

Affected software

Adobe Commerce (formerly Magento Commerce)

Remediation

Update to version 2.0.16 or 2.1.9.


External References

Related Security Bulletins