In Magento to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layout modification.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5009 | In Magento to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layout modification. |
Github GHSA |
GHSA-qpc8-m2xm-9w75 | Magento Remote code execution through catalog attribute sets |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://magento.com/security/patches/supee-11219 |
|
History
No history.
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-08-04T21:10:33.540Z
Reserved: 2019-02-12T00:00:00.000Z
Link: CVE-2019-8231
No data.
Status : Modified
Published: 2019-11-06T00:15:13.140
Modified: 2024-11-21T04:49:32.210
Link: CVE-2019-8231
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA