CVE-2021-41143 – OpenMage LTS arbitrary file deletion in customer media allows for remote code execution
https://notcve.org/view.php?id=CVE-2021-41143
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute code on the server. Versions 19.4.22 and 20.0.19 contain a patch for this issue. OpenMage LTS es una plataforma de comercio electrónico. Antes de las versiones 19.4.22 y 20.0.19, los usuarios administradores de Magento con acceso a los medios del cliente podían ejecutar código en el servidor. • https://github.com/OpenMage/magento-lts/commit/45330ff50439984e806992fa22c3f96c4d660f91 https://github.com/OpenMage/magento-lts/releases/tag/v19.4.22 https://github.com/OpenMage/magento-lts/releases/tag/v20.0.19 https://github.com/OpenMage/magento-lts/security/advisories/GHSA-5vpv-xmcj-9q85 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2021-39217 – OpenMage LTS arbitrary command execution in custom layout update through blocks
https://notcve.org/view.php?id=CVE-2021-39217
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 and 20.0.19 contain patches for this issue. OpenMage LTS es una plataforma de comercio electrónico. Antes de las versiones 19.4.22 y 20.0.19, el diseño personalizado permitía a los usuarios administradores ejecutar comandos arbitrarios mediante métodos de bloqueo. • https://github.com/OpenMage/magento-lts/commit/289bd4b4f53622138e3e5c2d2cef7502d780086f https://github.com/OpenMage/magento-lts/releases/tag/v19.4.22 https://github.com/OpenMage/magento-lts/releases/tag/v20.0.19 https://github.com/OpenMage/magento-lts/security/advisories/GHSA-c9q3-r4rv-mjm7 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2021-21395 – Magneto-lts vulnerable to Cross-Site Request Forgery
https://notcve.org/view.php?id=CVE-2021-21395
Magneto LTS (Long Term Support) is a community developed alternative to the Magento CE official releases. Versions prior to 19.4.22 and 20.0.19 are vulnerable to Cross-Site Request Forgery. The password reset form is vulnerable to CSRF between the time the reset password link is clicked and user submits new password. This issue is patched in versions 19.4.22 and 20.0.19. There are no workarounds. • https://github.com/OpenMage/magento-lts/security/advisories/GHSA-r3c9-9j5q-pwv4 https://hackerone.com/reports/1086752 https://packagist.org/packages/openmage/magento-lts • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2021-32759 – Data Flow Sanitation Issue Fix
https://notcve.org/view.php?id=CVE-2021-32759
OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in versions prior to 19.4.15 and 20.0.13, it was possible for admin users to upload arbitrary executable files to the server. OpenMage versions 19.4.15 and 20.0.13 have a patch for this Issue. OpenMage magento-lts es una alternativa a las versiones oficiales de Magento CE. Debido a una falta de saneamiento en el flujo de datos en las versiones anteriores a 19.4.15 y 20.0.13, era posible que los usuarios administradores cargaran archivos ejecutables arbitrarios al servidor. • https://github.com/OpenMage/magento-lts/releases/tag/v19.4.15 https://github.com/OpenMage/magento-lts/releases/tag/v20.0.13 https://github.com/OpenMage/magento-lts/security/advisories/GHSA-xm9f-vxmx-4m58 • CWE-20: Improper Input Validation •
CVE-2021-32758 – Layout XML Arbitrary Code Fix
https://notcve.org/view.php?id=CVE-2021-32758
OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layout XML enabled admin users to execute arbitrary commands via block methods. The latest OpenMage Versions up from v19.4.15 and v20.0.11 have this Issue patched. OpenMage Magento LTS es una alternativa a las versiones oficiales de Magento CE. Anterior a versiones 19.4.15 y 20.0.11, el diseño XML permitía a usuarios administradores ejecutar comandos arbitrarioss por medio de métodos de bloqueo. • https://github.com/OpenMage/magento-lts/releases/tag/v19.4.15 https://github.com/OpenMage/magento-lts/releases/tag/v20.0.11 https://github.com/OpenMage/magento-lts/security/advisories/GHSA-26rr-v2j2-25fh • CWE-91: XML Injection (aka Blind XPath Injection) •