Information disclosure in Adobe Commerce (formerly Magento Commerce) - #VU8474

 

Information disclosure in Adobe Commerce (formerly Magento Commerce) - #VU8474

Published: September 15, 2017


Vulnerability identifier: #VU8474
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker can gain access to potentially sensitive information.

The vulnerability exists due to the Magento email replies to product requests expose the system path of the Magento installation. A remote attacker can leverage the system path to enable the use of other vulnerabilities.

Affected software

Adobe Commerce (formerly Magento Commerce)

Remediation

Update to version 2.0.16 or 2.1.9.


External References

Related Security Bulletins