Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Layout XML Arbitrary Code Fix
Vulnerability Description
OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layout XML enabled admin users to execute arbitrary commands via block methods. The latest OpenMage Versions up from v19.4.15 and v20.0.11 have this Issue patched.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
XML注入(XPath盲注)
Vulnerability Title
OpenMage Magento Lts 输入验证错误漏洞
Vulnerability Description
OpenMage Magento Lts(Magento)是OpenMage组织的一个电子商务系统。 OpenMage Magento LTS 19.4.15和20.0.13之前版本存在输入验证错误漏洞,管理员用户能够通过块方法执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A