Allele Security Alert
ASA-2019-00399
Identifier(s)
ASA-2019-00399, CVE-2019-7871, PRODSECBUG-2202
Title
Security bypass via form data injection
Vendor(s)
Magento, Inc.
Product(s)
Magento
Affected version(s)
Magento 2.1.x versions prior to 2.1.18
Magento 2.2.x versions prior to 2.2.9
Magento 2.3.x versions prior to 2.3.2
Fixed version(s)
Magento version 2.1.18
Magento version 2.2.9
Magento version 2.3.2
Proof of concept
Unknown
Description
An authenticated user can inject form data and bypass security protections that prevent arbitrary PHP script upload.
Technical details
Unknown
Credits
Max Chadwick
Reference(s)
Magento 2.3.2, 2.2.9 and 2.1.18 Security Update 1/3
https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13
CVE-2019-7871
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7871
CVE-2019-7871
https://nvd.nist.gov/vuln/detail/CVE-2019-7871
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: July 24, 2019