ASA-2019-00397 – Magento: Arbitrary code execution through product imports and design layout update


Allele Security Alert

ASA-2019-00397

Identifier(s)

ASA-2019-00397, CVE-2019-7896, PRODSECBUG-2298

Title

Arbitrary code execution through product imports and design layout update

Vendor(s)

Magento, Inc.

Product(s)

Magento

Affected version(s)

Magento 2.1.x versions prior to 2.1.18
Magento 2.2.x versions prior to 2.2.9
Magento 2.3.x versions prior to 2.3.2

Fixed version(s)

Magento 2.1.18
Magento 2.2.9
Magento 2.3.2

Proof of concept

Unknown

Description

An authenticated user with admin privileges can execute arbitrary code through combination of product import via crafted csv file and XML layout update.

Technical details

Unknown

Credits

Edgar Boda-Majer

Reference(s)

PRODSECBUG-2296: Arbitrary code execution through design layout update – CVE-2019-7895
https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13

CVE-2019-7896
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7896

CVE-2019-7896
https://nvd.nist.gov/vuln/detail/CVE-2019-7896

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: June 29, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.