PT-2021-14499 · Unknown · Magento-Lts
Highflyingmana
·
Published
2021-04-21
·
Updated
2021-04-30
·
CVE-2021-21427
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
magento-lts versions prior to 19.4.13
magento-lts versions prior to 20.0.9
Description
A vulnerability in magento-lts potentially allows an administrator unauthorized access to restricted resources. This issue is related to a SQL injection vulnerability in the MySQL adapter.
Recommendations
For versions prior to 19.4.13, update to version 19.4.13 to resolve the issue.
For versions prior to 20.0.9, update to version 20.0.9 to resolve the issue.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Magento-Lts