Allele Security Alert
ASA-2019-00397, CVE-2019-7896, PRODSECBUG-2298
Arbitrary code execution through product imports and design layout update
Magento 2.1.x versions prior to 2.1.18
Magento 2.2.x versions prior to 2.2.9
Magento 2.3.x versions prior to 2.3.2
Proof of concept
An authenticated user with admin privileges can execute arbitrary code through combination of product import via crafted csv file and XML layout update.
PRODSECBUG-2296: Arbitrary code execution through design layout update – CVE-2019-7895
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: June 29, 2019