ASA-2019-00399 – Magento: Security bypass via form data injection


Allele Security Alert

ASA-2019-00399

Identifier(s)

ASA-2019-00399, CVE-2019-7871, PRODSECBUG-2202

Title

Security bypass via form data injection

Vendor(s)

Magento, Inc.

Product(s)

Magento

Affected version(s)

Magento 2.1.x versions prior to 2.1.18
Magento 2.2.x versions prior to 2.2.9
Magento 2.3.x versions prior to 2.3.2

Fixed version(s)

Magento version 2.1.18
Magento version 2.2.9
Magento version 2.3.2

Proof of concept

Unknown

Description

An authenticated user can inject form data and bypass security protections that prevent arbitrary PHP script upload.

Technical details

Unknown

Credits

Max Chadwick

Reference(s)

Magento 2.3.2, 2.2.9 and 2.1.18 Security Update 1/3
https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-13

CVE-2019-7871
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7871

CVE-2019-7871
https://nvd.nist.gov/vuln/detail/CVE-2019-7871

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: July 24, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.