CVE-2019-7859: Path Traversal
A path traversal vulnerability in the WYSIWYG editor for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could result in unauthorized access to uploaded images due to insufficient access control.
Other sources
PRODSECBUG-2173: Path traversal vulnerability in WYSIWYG editor.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7859?
CVE-2019-7859 is classified as a high-severity path traversal vulnerability affecting certain versions of Magento.
How do I fix CVE-2019-7859?
To fix CVE-2019-7859, you should update Magento to version 2.1.18, 2.2.9, or 2.3.2 to mitigate the vulnerability.
Which versions of Magento are affected by CVE-2019-7859?
CVE-2019-7859 affects Magento versions 2.1 before 2.1.18, 2.2 before 2.2.9, and 2.3 before 2.3.2.
What kind of vulnerability is CVE-2019-7859?
CVE-2019-7859 is a path traversal vulnerability that can lead to unauthorized access to uploaded images.
What should I do if I cannot update Magento for CVE-2019-7859?
If you cannot update Magento, it is recommended to implement additional access controls to restrict image access until you can upgrade.