OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 and 20.0.19 contain patches for this issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0442 | OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 and 20.0.19 contain patches for this issue. |
Github GHSA |
GHSA-c9q3-r4rv-mjm7 | Fix for arbitrary command execution in custom layout update through blocks |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 10 Mar 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-10T21:18:43.503Z
Reserved: 2021-08-16T20:13:27.756Z
Link: CVE-2021-39217
Updated: 2024-08-04T01:58:18.185Z
Status : Modified
Published: 2023-01-27T18:15:09.087
Modified: 2024-11-21T06:18:55.717
Link: CVE-2021-39217
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA