CVE-2021-21064: Magento UPWARD-php Path traversal vulnerability via UPWARD Connector
Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal vulnerability in Magento UPWARD Connector version 1.1.2 (and earlier) due to the upload feature. An attacker could potentially exploit this vulnerability to upload a malicious YAML file that can contain instructions which allows reading arbitrary files from the remote server. Access to the admin console is required for successful exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Magento UPWARD-php vulnerability?
The vulnerability ID for this Magento UPWARD-php vulnerability is CVE-2021-21064.
What is the severity of CVE-2021-21064?
The severity of CVE-2021-21064 is medium with a severity value of 4.9.
Which software versions are affected by CVE-2021-21064?
Magento UPWARD Connector version 1.1.2 (and earlier) and Magento UPWARD-php version 1.1.4 (and earlier) are affected by CVE-2021-21064.
How does CVE-2021-21064 vulnerability work?
CVE-2021-21064 is a Path traversal vulnerability in Magento UPWARD Connector that can be exploited by uploading a malicious YAML file containing instructions.
How can I fix CVE-2021-21064?
To fix CVE-2021-21064, upgrade to Magento UPWARD Connector version 1.1.3 or later and Magento UPWARD-php version 1.1.5 or later.