VYPR

Upward PHP

by Magento

CVEs (1)

  • CVE-2021-21064MedFeb 25, 2021
    risk 0.33cvss 4.9epss 0.09

    Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal vulnerability in Magento UPWARD Connector version 1.1.2 (and earlier) due to the upload feature. An attacker could potentially exploit this vulnerability to upload a malicious YAML file that can…