VDB
Sign up
HIGH8.8

GHSA-6qh6-v99h-vh4c

Magento 2 Community Edition RCE Vulnerability

Quick fix

GHSA-6qh6-v99h-vh4c — magento/community-edition: upgrade to the fixed version with the command below.

composer require magento/community-edition:^2.1.18

Details

A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to manipulate layouts can insert a malicious payload into the layout.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/magento/community-edition
Introduced in: 2.1Fixed in: 2.1.18
Fixcomposer require magento/community-edition:^2.1.18
Packagist/magento/community-edition
Introduced in: 2.2Fixed in: 2.2.9
Fixcomposer require magento/community-edition:^2.2.9
Packagist/magento/community-edition
Introduced in: 2.3Fixed in: 2.3.2
Fixcomposer require magento/community-edition:^2.3.2
Packagist/magento/product-community-edition
Introduced in: 2.1Fixed in: 2.1.18
Fixcomposer require magento/product-community-edition:^2.1.18
Packagist/magento/product-community-edition
Introduced in: 2.2Fixed in: 2.2.9
Fixcomposer require magento/product-community-edition:^2.2.9
Packagist/magento/product-community-edition
Introduced in: 2.3Fixed in: 2.3.2
Fixcomposer require magento/product-community-edition:^2.3.2

References