VDB
Sign up
HIGH8.8

GHSA-5j2g-3ph4-rgvm

Fix for authenticated remote code execution through layout update

Quick fix

GHSA-5j2g-3ph4-rgvm — openmage/magento-lts: upgrade to the fixed version with the command below.

composer require openmage/magento-lts:^19.4.22

Details

### Impact A layout block was able to bypass the block blacklist to execute remote code.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/openmage/magento-lts
Introduced in: 0Fixed in: 19.4.22
Fixcomposer require openmage/magento-lts:^19.4.22
Packagist/openmage/magento-lts
Introduced in: 20.0.0Fixed in: 20.0.19
Fixcomposer require openmage/magento-lts:^20.0.19

References