OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layout XML enabled admin users to execute arbitrary commands via block methods. The latest OpenMage Versions up from v19.4.15 and v20.0.11 have this Issue patched.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1505 | OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layout XML enabled admin users to execute arbitrary commands via block methods. The latest OpenMage Versions up from v19.4.15 and v20.0.11 have this Issue patched. |
Github GHSA |
GHSA-26rr-v2j2-25fh | Layout XML Arbitrary Code Fix |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-03T23:33:55.894Z
Reserved: 2021-05-12T00:00:00
Link: CVE-2021-32758
No data.
Status : Modified
Published: 2021-08-27T18:15:07.173
Modified: 2024-11-21T06:07:40.870
Link: CVE-2021-32758
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA