Path traversal in Adobe Commerce (formerly Magento Commerce) - #VU8462

 

Path traversal in Adobe Commerce (formerly Magento Commerce) - #VU8462

Published: September 15, 2017


Vulnerability identifier: #VU8462
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to view contents of arbitrary files on the system.

The vulnerability exists due to insufficient input validation in Delete Files module. A remote administrator with limited privileges can view or delete arbitrary files on the target system.

Affected software

Adobe Commerce (formerly Magento Commerce)

Remediation

Update to version 2.0.16 or 2.1.9.


External References

Related Security Bulletins