CVE-2019-7861

HIGH

Magento <2.1.18-2.3.2 - Auth Bypass

Title source: llm
STIX 2.1

Description

Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0006
EPSS Percentile 18.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-434
Status published
Products (2)
magento/community-edition 2.1.0 - 2.1.18Packagist
magento/magento 2.1.0 - 2.1.18
Published Aug 02, 2019
Tracked Since Feb 18, 2026