Описание
OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in versions prior to 19.4.15 and 20.0.13, it was possible for admin users to upload arbitrary executable files to the server. OpenMage versions 19.4.15 and 20.0.13 have a patch for this Issue.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 19.4.13 (исключая)Версия от 20.0.0 (включая) до 20.0.11 (исключая)
Одно из
cpe:2.3:a:openmage:magento:*:*:*:*:*:*:*:*
cpe:2.3:a:openmage:magento:*:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.0055
Низкий
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-20
CWE-20
Связанные уязвимости
EPSS
Процентиль: 67%
0.0055
Низкий
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-20
CWE-20