Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Magento's X-Original-Url header can expose admin url
Vulnerability Description
Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. This issue has been patched in version 20.16.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
magento-lts 信息泄露漏洞
Vulnerability Description
magento-lts是OpenMage开源的一个用于Magento CE官方版本的可靠替代品。 Magento-lts 20.16.1之前版本存在信息泄露漏洞,该漏洞源于在某些配置下可利用X-Original-Url标头发现管理员URL。
CVSS Information
N/A
Vulnerability Type
N/A