CVE-2019-7861
Description
Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
CWE
- (none)
Affected
- n/a / Magento 2 — v=Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 [affected]
CVSS
- (none)
References
- https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13 x_refsource_CONFIRM
Source
cvelistV5-main/cves/2019/7xxx/CVE-2019-7861.json