Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29499
HistoryFeb 26, 2021 - 1:58 a.m.

Directory Traversal

2021-02-2601:58:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
directory traversal
magento
software vulnerability
yaml file upload

EPSS

0.001

Percentile

30.8%

magento/module-upward-connector is vulnerable to directory traversal. An attacker with a privilege to access Admin Console is able to upload a malicious YAML file to read arbitrary files from the remote server.

EPSS

0.001

Percentile

30.8%

Related for VERACODE:29499