Improper access control in Adobe Commerce (formerly Magento Commerce) - #VU8484

 

Improper access control in Adobe Commerce (formerly Magento Commerce) - #VU8484

Published: September 15, 2017


Vulnerability identifier: #VU8484
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote administrator to change favicon icon for entire website.

A Magento administrator with limited privileges can update the Favicon image for the entire site.

Affected software

Adobe Commerce (formerly Magento Commerce)

Remediation

Update to version 2.0.16 or 2.1.9.


External References

Related Security Bulletins