CVE-2021-21064

MEDIUM

Magento UPWARD-php <1.1.4 - Path Traversal

Title source: llm
STIX 2.1

Description

Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal vulnerability in Magento UPWARD Connector version 1.1.2 (and earlier) due to the upload feature. An attacker could potentially exploit this vulnerability to upload a malicious YAML file that can contain instructions which allows reading arbitrary files from the remote server. Access to the admin console is required for successful exploitation.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://github.com/magento/upward-php/security

Scores

CVSS v3 4.9
EPSS 0.0094
EPSS Percentile 76.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (2)
magento/upward_connector < 1.1.2
magento/upward_php < 1.1.4
Published Feb 25, 2021
Tracked Since Feb 18, 2026