CVE-2021-39217

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
27/01/2023
Last modified:
04/02/2023

Description

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 and 20.0.19 contain patches for this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:* 19.4.22 (excluding)
cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:* 20.0.0 (including) 20.0.19 (excluding)