Description
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. Versions 19.4.22 and 20.0.19 contain a patch for this issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0479 | OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. Versions 19.4.22 and 20.0.19 contain a patch for this issue. |
Github GHSA |
GHSA-h632-p764-pjqm | DataFlow upload remote code execution vulnerability |
References
History
Mon, 10 Mar 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-10T21:18:26.133Z
Reserved: 2021-09-15T18:43:17.291Z
Link: CVE-2021-41231
Updated: 2024-08-04T03:08:31.607Z
Status : Modified
Published: 2023-01-27T19:15:10.197
Modified: 2024-11-21T06:25:50.460
Link: CVE-2021-41231
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA