CVE-2021-39217
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
27/01/2023
Last modified:
04/02/2023
Description
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 and 20.0.19 contain patches for this issue.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:* | 19.4.22 (excluding) | |
| cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:* | 20.0.0 (including) | 20.0.19 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



