Description
In Magento to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layout modification.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5009 | In Magento to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layout modification. |
Github GHSA |
GHSA-qpc8-m2xm-9w75 | Magento Remote code execution through catalog attribute sets |
References
| Link | Providers |
|---|---|
| https://magento.com/security/patches/supee-11219 |
|
History
No history.
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-08-04T21:10:33.540Z
Reserved: 2019-02-12T00:00:00.000Z
Link: CVE-2019-8231
No data.
Status : Modified
Published: 2019-11-06T00:15:13.140
Modified: 2024-11-21T04:49:32.210
Link: CVE-2019-8231
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA