CVE-2019-7912 is a file upload filter bypass vulnerability affecting Magento 2.1, 2.2, and 2.3 versions prior to their respective patched releases. An authenticated administrator can exploit this to remove file extension filters, enabling the upload and execution of malicious files. This vulnerability carries a CVSS score of 7.2 (HIGH), indicating a network-based attack with high impact on confidentiality, integrity, and availability, requiring high privileges but no user interaction. While no active exploitation or public exploit code is reported, and community discussion is minimal, organizations using affected Magento versions should prioritize patching to mitigate this significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.1.0, < 2.1.18CPE matchmatch criteria | cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* | ||
>= 2.2.0, < 2.2.9CPE matchmatch criteria | cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* | ||
>= 2.3.0, < 2.3.2CPE matchmatch criteria | cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.