Lucene search

K
osvGoogleOSV:CVE-2021-21064
HistoryFeb 25, 2021 - 2:15 p.m.

CVE-2021-21064

2021-02-2514:15:12
Google
osv.dev
7
magento
upward connector
path traversal
vulnerability
yaml file
remote server
exploitation
admin console
upload feature

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

30.8%

Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal vulnerability in Magento UPWARD Connector version 1.1.2 (and earlier) due to the upload feature. An attacker could potentially exploit this vulnerability to upload a malicious YAML file that can contain instructions which allows reading arbitrary files from the remote server. Access to the admin console is required for successful exploitation.

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

30.8%

Related for OSV:CVE-2021-21064