First published: Fri Jan 27 2023(Updated: )
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the block blacklist to execute remote code. Versions 19.4.22 and 20.0.19 contain a patch for this issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenMage | <19.4.22 | |
OpenMage | >=20.0.0<20.0.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41144 is a vulnerability in OpenMage LTS, an e-commerce platform, that allows a layout block to bypass the block blacklist and execute remote code.
Versions prior to 19.4.22 and 20.0.19 of OpenMage LTS are affected by CVE-2021-41144.
CVE-2021-41144 has a severity rating of high with a CVSS score of 8.8.
To fix CVE-2021-41144, update your OpenMage LTS installation to versions 19.4.22 or 20.0.19 which contain the patch for this vulnerability.
You can find more information about CVE-2021-41144 on the following references: [Reference 1](https://github.com/OpenMage/magento-lts/commit/06c45940ba3256cdfc9feea12a3c0ca56d23acf8), [Reference 2](https://github.com/OpenMage/magento-lts/releases/tag/v19.4.22), [Reference 3](https://github.com/OpenMage/magento-lts/releases/tag/v20.0.19).