CVE-2021-21064 MEDIUM

CVE-2021-21064: Magento UPWARD-php Path traversal vulnerability via UPWARD Connector

Vendor Adobe
Product Magento Commerce
Weakness CWE-22 · Path traversal
Published February 25, 2021
Last update September 16, 2024

CVSS base score

4.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

Description

Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal vulnerability in Magento UPWARD Connector version 1.1.2 (and earlier) due to the upload feature. An attacker could potentially exploit this vulnerability to upload a malicious YAML file that can contain instructions which allows reading arbitrary files from the remote server. Access to the admin console is required for successful exploitation.

Key dates

Disclosure timeline

February 25, 2021 CVE published
September 16, 2024 Record updated