cve-2018-9995

1 article
sort: new top best
clear filter
0 8/10

Two vulnerabilities in Magento e-commerce CMS exploitable by low-privilege admin accounts: (1) Remote Code Execution via path traversal in product design layout XML combined with phtml file upload through custom options, and (2) Local File Read through path traversal in email template CSS directive processing.

Magento Adobe Experience Cloud SCRT Team Magento 2.3.0 Magento 2.2.7 Magento 2.1.16
blog.scrt.ch · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details