PT-2026-37254 · Openmage+1 · Magento-Lts+1

Published

2026-05-05

·

Updated

2026-05-18

·

CVE-2026-42207

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Magento Long Term Support (LTS) versions prior to 20.18.0
Description The Mage ProductAlert AddController::stockAction() function reads the uenc query parameter and passes it directly to $this-> redirectUrl($backUrl) without verifying if the URL is internal via $this-> isUrlInternal(). When a provided product id does not match any catalog product, the server performs an unvalidated HTTP 302 redirect to the URL specified in the uenc parameter. This allows an attacker to redirect authenticated users to arbitrary external websites, which can be used for credential phishing, stealing OAuth tokens, or malware distribution.
Recommendations Update to version 20.18.0.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2026-42207
GHSA-QPGQ-5G92-J5Q8

Affected Products

Magento-Lts
Openmage Magento Lts