Lucene search

K
osvGoogleOSV:CVE-2021-28566
HistorySep 08, 2021 - 5:15 p.m.

CVE-2021-28566

2021-09-0817:15:09
Google
osv.dev
3
magento
information disclosure
png
vulnerability
unauthenticated attacker
admin console

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

27.3%

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Information Disclosure vulnerability when uploading a modified png file to a product image. Successful exploitation could lead to the disclosure of document root path by an unauthenticated attacker. Access to the admin console is required for successful exploitation.

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

27.3%

Related for OSV:CVE-2021-28566