Description
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 and 20.0.19 contain patches for this issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0442 | OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 and 20.0.19 contain patches for this issue. |
Github GHSA |
GHSA-c9q3-r4rv-mjm7 | Fix for arbitrary command execution in custom layout update through blocks |
References
History
Mon, 10 Mar 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-10T21:18:43.503Z
Reserved: 2021-08-16T20:13:27.756Z
Link: CVE-2021-39217
Updated: 2024-08-04T01:58:18.185Z
Status : Modified
Published: 2023-01-27T18:15:09.087
Modified: 2024-11-21T06:18:55.717
Link: CVE-2021-39217
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA