PT-2023-12374 · Unknown · Openmage Lts
Highmark-Netalico
·
Publicado
2023-01-27
·
Atualizado
2023-07-17
·
CVE-2021-41143
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenMage LTS versions prior to 19.4.22
OpenMage LTS versions prior to 20.0.19
Description
The issue affects OpenMage LTS, an e-commerce platform. Magento admin users with access to the customer media could execute code on the server.
Recommendations
For versions prior to 19.4.22, update to version 19.4.22 or later.
For versions prior to 20.0.19, update to version 20.0.19 or later.
Correção
Command Injection
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openmage Lts