OpenMage LTS authenticated remote code execution through layout update
CVE-2021-41144
8.8HIGH
What is CVE-2021-41144?
A remote code execution vulnerability exists in OpenMage LTS, a popular e-commerce platform. Prior to version 19.4.22 and 20.0.19, a flaw allowed layout blocks to bypass a blacklist, potentially leading to unauthorized remote code execution. This vulnerability has been addressed in the newer versions, ensuring better security for users.
Affected Version(s)
magento-lts < 19.4.22 < 19.4.22
magento-lts >= 20.0.0, < 20.0.19 < 20.0.0, 20.0.19
