CVE-2019-7861: Malicious File Upload
Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
Other sources
PRODSECBUG-2177: Insufficient server side validations leads to Insecure File upload vulnerability
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7861?
CVE-2019-7861 has a medium severity rating due to its potential for unauthorized file uploads.
How do I fix CVE-2019-7861?
To address CVE-2019-7861, upgrade your Magento installation to version 2.1.18, 2.2.9, or 2.3.2 or later.
Which versions of Magento are affected by CVE-2019-7861?
CVE-2019-7861 affects Magento 2.1 versions before 2.1.18, 2.2 before 2.2.9, and 2.3 before 2.3.2.
What type of attack does CVE-2019-7861 allow?
CVE-2019-7861 allows attackers to bypass file upload restrictions due to insufficient server-side validation.
Is CVE-2019-7861 a critical vulnerability?
CVE-2019-7861 is not classified as critical, but it poses a significant risk if not patched.