GHSA-hqhf-8jgc-h5hx
Dashboard / Vulnerabilities / GHSA-hqhf-8jgc-h5hx
Summary: Magento 2 Community Edition Path Traversal Vulnerability
Details: A path traversal vulnerability in the WYSIWYG editor for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could result in unauthorized access to uploaded images due to insufficient access control.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-7859, https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2019-7859.yaml, https://github.com/magento/magento2, https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-23, https://web.archive.org/web/20220127030535/https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-24
Affected packages
Package
Name: magento/community-edition
Purl: pkg:composer/magento/community-edition
Affected ranges
Type: ECOSYSTEM
Events:
