CVE-2019-7925: Path Traversal
An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an administrator with limited privileges to delete the downloadable products folder.
Other sources
PRODSECBUG-2343: Insecure Direct Object Reference (IDOR) vulnerability can lead to deletion of downloadable products folder
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7925?
CVE-2019-7925 is classified as a high severity vulnerability due to the potential for unauthorized deletion of important product data.
How do I fix CVE-2019-7925?
To fix CVE-2019-7925, upgrade Magento to version 2.3.2, 2.2.9, or 2.1.18 or later.
What types of products are affected by CVE-2019-7925?
CVE-2019-7925 affects downloadable products in Magento versions prior to the fixed releases.
Who can exploit CVE-2019-7925?
CVE-2019-7925 can be exploited by administrators with limited privileges.
What does CVE-2019-7925 allow an attacker to do?
CVE-2019-7925 allows an attacker to delete the downloadable products folder, potentially impacting product availability.