PT-2021-11232 · Openmage · Openmage
Published
2021-01-21
·
Updated
2021-01-28
·
CVE-2020-26285
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
OpenMage versions prior to 19.4.10
OpenMage versions prior to 20.0.5
Description:
OpenMage is a community-driven alternative to Magento CE. The issue enables remote code execution. An administrator with permission to import/export data and to create widget instances was able to inject an executable file on the server.
Recommendations:
For versions prior to 19.4.10, update to version 19.4.10 or later.
For versions prior to 20.0.5, update to version 20.0.5 or later.
Fix
Unrestricted File Upload
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openmage