Description
An arbitrary file deletion vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated users can manipulate the design layout update feature.
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://magento.com/security/patches/magento-2.3.3-and-2.2.10-security-update
Scores
CVSS v3
6.5
EPSS
0.0011
EPSS Percentile
28.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Details
Status
published
Products (3)
magento/community-edition
2.2.0 - 2.2.10Packagist
magento/magento
2.3.2 (2 CPE variants)
magento/magento
2.1.0 - 2.1.19 (2 CPE variants)
Published
Nov 05, 2019
Tracked Since
Feb 18, 2026