CVE-2019-7930: Malicious File Upload
A file upload restriction bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with administrator privileges to the import feature can make modifications to a configuration file, resulting in potentially unauthorized removal of file upload restrictions. This can result in arbitrary code execution when a malicious file is then uploaded and executed on the system.
Other sources
PRODSECBUG-2349: Arbitrary code execution via file upload in admin import feature
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7930?
CVE-2019-7930 has a medium severity rating that could allow an authenticated user to bypass file upload restrictions.
How do I fix CVE-2019-7930?
To fix CVE-2019-7930, you should upgrade Magento to version 2.1.18, 2.2.9, or 2.3.2, which addresses this vulnerability.
What systems are affected by CVE-2019-7930?
CVE-2019-7930 affects Magento versions 2.1 prior to 2.1.18, 2.2 prior to 2.2.9, and 2.3 prior to 2.3.2.
Who can exploit CVE-2019-7930?
CVE-2019-7930 can be exploited by authenticated users with administrator privileges in Magento.
What risks are associated with CVE-2019-7930?
Exploitation of CVE-2019-7930 could lead to unauthorized modifications to configuration files and potentially compromise the integrity of the Magento application.