CVE-2023-26367: Error based file extraction via PHP filter chains during product bulk import logic
Published Oct 13, 2023
·Updated
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read by an admin-privilege authenticated attacker. Exploitation of this issue does not require user interaction.
Affected Software
67 affected componentsFixes available
composer/magento/project-community-edition<=2.0.2
composer/magento/community-edition>=2.4.4-p1<2.4.4-p6
2.4.4-p6
composer/magento/community-edition>=2.4.5-p1<2.4.5-p5
2.4.5-p5
composer/magento/community-edition>=2.4.6-p1<2.4.6-p3
2.4.6-p3
composer/magento/community-edition=2.4.4
composer/magento/community-edition=2.4.5
composer/magento/community-edition=2.4.6
composer/magento/community-edition=2.4.7
composer/magento/community-edition=2.4.7-beta1
2.4.7-beta2
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
Adobe Commerce=2.3.7-p4-ext2
Adobe Commerce=2.3.7-p4-ext3
Adobe Commerce=2.3.7-p4-ext4
Adobe Commerce=2.4.0
Adobe Commerce=2.4.0-ext-1
Adobe Commerce=2.4.0-ext-2
Adobe Commerce=2.4.0-ext-3
Adobe Commerce=2.4.0-ext-4
Adobe Commerce=2.4.1
Adobe Commerce=2.4.1-ext-1
Adobe Commerce=2.4.1-ext-2
Adobe Commerce=2.4.1-ext-3
Adobe Commerce=2.4.1-ext-4
Adobe Commerce=2.4.2
Adobe Commerce=2.4.2-ext-1
Adobe Commerce=2.4.2-ext-2
Adobe Commerce=2.4.2-ext-3
Adobe Commerce=2.4.2-ext-4
Adobe Commerce=2.4.3
Adobe Commerce=2.4.3-ext-1
Adobe Commerce=2.4.3-ext-2
Adobe Commerce=2.4.3-ext-3
Adobe Commerce=2.4.3-ext-4
Adobe Commerce=2.4.4
Adobe Commerce=2.4.4-p1
Adobe Commerce=2.4.4-p2
Adobe Commerce=2.4.4-p3
Adobe Commerce=2.4.4-p4
Adobe Commerce=2.4.4-p5
Adobe Commerce=2.4.5
Adobe Commerce=2.4.5-p1
Adobe Commerce=2.4.5-p2
Adobe Commerce=2.4.5-p3
Adobe Commerce=2.4.5-p4
Adobe Commerce=2.4.5-p5
Adobe Commerce=2.4.6
Adobe Commerce=2.4.6-p1
Adobe Commerce=2.4.6-p2
Adobe Commerce=2.4.7-b1
Adobe Magento=2.4.4
Adobe Magento=2.4.4-p1
Adobe Magento=2.4.4-p2
Adobe Magento=2.4.4-p3
Adobe Magento=2.4.5
Adobe Magento=2.4.5-p1
Adobe Magento=2.4.5-p2
Adobe Magento=2.4.5-p3
Adobe Magento=2.4.5-p4
Adobe Magento=2.4.6
Adobe Magento=2.4.6-p1
Adobe Magento=2.4.6-p2
Adobe Magento=2.4.7-b1
Event History
Oct 13, 2023
CVE Published
via MITRE·06:15 AM
Data Sourced
via MITRE·06:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·09:30 AM