Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal vulnerability in Magento UPWARD Connector version 1.1.2 (and earlier) due to the upload feature. An attacker could potentially exploit this vulnerability to upload a malicious YAML file that can contain instructions which allows reading arbitrary files from the remote server. Access to the admin console is required for successful exploitation.
2021-02-25T14:15:12.143
2024-11-21T05:47:29.927
Modified
CVSSv3.0: 4.9 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | magento | upward_connector | ≤ 1.1.2 | Yes |
Application | magento | upward_php | ≤ 1.1.4 | Yes |