Path traversal in Adobe Commerce (formerly Magento Commerce) - #VU8465

 

Path traversal in Adobe Commerce (formerly Magento Commerce) - #VU8465

Published: September 15, 2017


Vulnerability identifier: #VU8465
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to view contents of arbitrary files on the system.

The vulnerability exists due to insufficient input validation in the sitemap functionality. A remote administrator with limited privileges can use the sitemap generation tool to arbitrarily overwrite sensitive files.

Affected software

Adobe Commerce (formerly Magento Commerce)

Remediation

Update to version 2.0.16 or 2.1.9.


External References

Related Security Bulletins