PT-2021-11236 · Openmage · Openmage

Mark-Netalico

·

Published

2021-01-21

·

Updated

2021-01-28

·

CVE-2020-26295

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: OpenMage versions prior to 19.4.10 OpenMage versions prior to 20.0.5
Description: OpenMage, a community-driven alternative to Magento CE, has an issue where an administrator with permission to import/export data and to edit CMS pages can inject an executable file on the server via layout XML.
Recommendations: For OpenMage versions prior to 19.4.10, update to version 19.4.10 or later. For OpenMage versions prior to 20.0.5, update to version 20.0.5 or later.

Fix

Unrestricted File Upload

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26295
GHSA-52C6-6V3V-F3FG

Affected Products

Openmage