OpenMage LTS arbitrary command execution in custom layout update through blocks
CVE-2021-39217
7.2HIGH
What is CVE-2021-39217?
OpenMage LTS, an e-commerce platform, is susceptible to a command execution vulnerability that allows admin users to execute arbitrary commands via block methods. This issue affects versions prior to 19.4.22 and 20.0.19. Patches addressing this vulnerability have been released in these versions, enhancing the security of the platform and protecting against unauthorized command execution.
Affected Version(s)
magento-lts < 19.4.22 < 19.4.22
magento-lts >= 20.0.0, < 20.0.19 < 20.0.0, 20.0.19
