CVE-2020-26295
CMS Editor code execution
Severity Score
7.2
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrator with permission to import/export data and to edit cms pages was able to inject an executable file on the server via layout xml. The latest OpenMage Versions up from 19.4.9 and 20.0.5 have this Issue solved
OpenMage es una alternativa impulsada por la comunidad a Magento CE. En OpenMage versiones anteriores a 19.4.10 y 20.0.5, un administrador con permiso para importar/exportar datos y editar páginas de cms podía inyectar un archivo ejecutable en el servidor a través de diseño xml. Las últimas versiones de OpenMage hasta 19.4.9 y 20.0.5 tienen este problema solucionado
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-10-01 CVE Reserved
- 2021-01-21 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/OpenMage/magento-lts/releases/tag/v19.4.10 | Third Party Advisory | |
https://github.com/OpenMage/magento-lts/security/advisories/GHSA-52c6-6v3v-f3fg | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/OpenMage/magento-lts/commit/9cf8c0aa1d1306051a18ace08d40279dadc1fb35 | 2021-01-28 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openmage Search vendor "Openmage" | Openmage Search vendor "Openmage" for product "Openmage" | < 19.4.10 Search vendor "Openmage" for product "Openmage" and version " < 19.4.10" | lts |
Affected
| ||||||
Openmage Search vendor "Openmage" | Openmage Search vendor "Openmage" for product "Openmage" | >= 20.0.0 < 20.0.5 Search vendor "Openmage" for product "Openmage" and version " >= 20.0.0 < 20.0.5" | lts |
Affected
|