PT-2021-19910 · Openmage · Openmage Magento Lts
Highmark-Netalico
·
Published
2021-08-27
·
Updated
2021-09-08
·
CVE-2021-32758
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenMage Magento LTS versions prior to 19.4.15
OpenMage Magento LTS versions prior to 20.0.11
Description
The issue allows admin users to execute arbitrary commands via block methods when layout XML is enabled. This can be exploited by admin users, potentially leading to unauthorized access and command execution.
Recommendations
For versions prior to 19.4.15, update to version 19.4.15 or later.
For versions prior to 20.0.11, update to version 20.0.11 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openmage Magento Lts