PT-2021-19910 · Openmage · Openmage Magento Lts

Highmark-Netalico

·

Published

2021-08-27

·

Updated

2021-09-08

·

CVE-2021-32758

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenMage Magento LTS versions prior to 19.4.15 OpenMage Magento LTS versions prior to 20.0.11
Description The issue allows admin users to execute arbitrary commands via block methods when layout XML is enabled. This can be exploited by admin users, potentially leading to unauthorized access and command execution.
Recommendations For versions prior to 19.4.15, update to version 19.4.15 or later. For versions prior to 20.0.11, update to version 20.0.11 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32758
GHSA-26RR-V2J2-25FH

Affected Products

Openmage Magento Lts