CVE-2021-41143

HIGH7.2EPSS 1.2%

Fix for arbitrary file deletion in customer media allows for remote code execution

發布日:2023/1/27修改日:2026/3/13

描述

### Impact Magento admin users with access to the customer media could execute code on the server.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

參考連結(6)