Логотип exploitDog
bind:CVE-2021-41231
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-41231

Количество 2

Количество 2

nvd логотип

CVE-2021-41231

около 3 лет назад

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. Versions 19.4.22 and 20.0.19 contain a patch for this issue.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-h632-p764-pjqm

около 3 лет назад

DataFlow upload remote code execution vulnerability

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-41231

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. Versions 19.4.22 and 20.0.19 contain a patch for this issue.

CVSS3: 7.2
1%
Низкий
около 3 лет назад
github логотип
GHSA-h632-p764-pjqm

DataFlow upload remote code execution vulnerability

CVSS3: 7.2
1%
Низкий
около 3 лет назад

Уязвимостей на страницу