
CVE-2021-32758 – Layout XML Arbitrary Code Fix
https://notcve.org/view.php?id=CVE-2021-32758
27 Aug 2021 — OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layout XML enabled admin users to execute arbitrary commands via block methods. The latest OpenMage Versions up from v19.4.15 and v20.0.11 have this Issue patched. OpenMage Magento LTS es una alternativa a las versiones oficiales de Magento CE. Anterior a versiones 19.4.15 y 20.0.11, el diseño XML permitía a usuarios administradores ejecutar comandos arbitrarioss por medio de métodos de bloqueo... • https://github.com/OpenMage/magento-lts/releases/tag/v19.4.15 • CWE-91: XML Injection (aka Blind XPath Injection) •

CVE-2021-21427 – Backport for CVE-2021-21024 Blind SQLi from Magento 2
https://notcve.org/view.php?id=CVE-2021-21427
21 Apr 2021 — Magento-lts is a long-term support alternative to Magento Community Edition (CE). A vulnerability in magento-lts versions before 19.4.13 and 20.0.9 potentially allows an administrator unauthorized access to restricted resources. This is a backport of CVE-2021-21024. The vulnerability is patched in versions 19.4.13 and 20.0.9. Magento-lts es una alternativa de soporte a largo plazo a Magento Community Edition (CE). • https://github.com/OpenMage/magento-lts/security/advisories/GHSA-fvrf-9428-527m • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-21426 – Fixes a bug in Zend Framework's Stream HTTP Wrapper
https://notcve.org/view.php?id=CVE-2021-21426
21 Apr 2021 — Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior and 20.0.8 and prior, there is a vulnerability caused by the unsecured deserialization of an object. A patch in versions 19.4.13 and 20.0.9 was back ported from Zend Framework 3. The vulnerability was assigned CVE-2021-3007 in Zend Framework. Magento-lts es una alternativa de soporte a largo plazo a Magento Community Edition (CE). • https://github.com/OpenMage/magento-lts/security/advisories/GHSA-m496-x567-f98c • CWE-502: Deserialization of Untrusted Data •

CVE-2020-26295 – CMS Editor code execution
https://notcve.org/view.php?id=CVE-2020-26295
21 Jan 2021 — OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrator with permission to import/export data and to edit cms pages was able to inject an executable file on the server via layout xml. The latest OpenMage Versions up from 19.4.9 and 20.0.5 have this Issue solved OpenMage es una alternativa impulsada por la comunidad a Magento CE. En OpenMage versiones anteriores a 19.4.10 y 20.0.5, un administrador con permiso para importar/exportar datos y e... • https://github.com/OpenMage/magento-lts/commit/9cf8c0aa1d1306051a18ace08d40279dadc1fb35 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2020-26285 – Widget instances allows a hacker to inject an executable file on the server on OpenMage
https://notcve.org/view.php?id=CVE-2020-26285
21 Jan 2021 — OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vulnerability which enables remote code execution. In affected versions an administrator with permission to import/export data and to create widget instances was able to inject an executable file on the server. The latest OpenMage Versions up from 19.4.9 and 20.0.5 have this Issue solved OpenMage es una alternativa impulsada por la comunidad a Magento CE. En OpenMage versiones anteriores a 19... • https://github.com/OpenMage/magento-lts/commit/4132668f5009f17456fe644742026f56d2297586 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2020-26252 – Layout XML RCE Vulnerability in OpenMage
https://notcve.org/view.php?id=CVE-2020-26252
20 Jan 2021 — OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vulnerability which enables remote code execution. In affected versions an administrator with permission to update product data to be able to store an executable file on the server and load it via layout xml. The latest OpenMage Versions up from 19.4.10 and 20.0.6 have this issue solved. OpenMage es una alternativa impulsada por la comunidad a Magento CE. • https://github.com/OpenMage/magento-lts/commit/0786aa48bc7b618cfe37b59f45e1da3714c533c3 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2020-15244 – RCE in Magento
https://notcve.org/view.php?id=CVE-2020-15244
21 Oct 2020 — In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product. The issue is patched in versions 19.4.8 and 20.0.4. En Magento (paquete rubygems openmage/magento-lts) versiones anteriores a 19.4.8 y 20.0.4, un usuario administrador puede generar credenciales soap que pueden ser usadas para activar una RCE por medio de la inyección de objetos PHP... • https://github.com/OpenMage/magento-lts • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-502: Deserialization of Untrusted Data •

CVE-2020-15151 – Observable Timing Discrepancy in OpenMage LTS
https://notcve.org/view.php?id=CVE-2020-15151
19 Aug 2020 — OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. This issue is related to Adobe's CVE-2020-9690. It is patched in versions 19.4.6 and 20.0.2. OpenMage LTS versiones anteriores a 19.4.6 y 20.0.2, permite a atacantes evitar la "fromkey protection" en la interfaz de Administración y aumenta la superficie de ataque para ataques de tipo Cross Site Request Forgery. ... • https://github.com/OpenMage/magento-lts/commit/7c526bc6a6a51b57a1bab4c60f104dc36cde347a • CWE-203: Observable Discrepancy CWE-352: Cross-Site Request Forgery (CSRF) •