Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-26hq-7286-mg8f

Опубликовано: 15 мая 2024
Источник: github
Github: Прошло ревью

Описание

Magento Patch SUPEE-9652 - Remote Code Execution using mail vulnerability

Zend Framework 1 vulnerability can be remotely exploited to execute code in Magento 1. While the issue is not reproducible in Magento 2, the library code is the same so it was fixed as well.

Note: while the vulnerability is scored as critical, few systems are affected. To be affected by the vulnerability the installation has to:

  • use sendmail as the mail transport agent

  • have specific, non-default configuration settings as described here.

Пакеты

Наименование

magento/community-edition

composer
Затронутые версииВерсия исправления

>= 1.9.0.0, < 1.14.3.2

1.14.3.2