VDB
Sign up
CRITICAL9.1

GHSA-fvrf-9428-527m

Backport for CVE-2021-21024 Blind SQLi from Magento 2

Quick fix

GHSA-fvrf-9428-527m — openmage/magento-lts: upgrade to the fixed version with the command below.

composer require openmage/magento-lts:^19.4.13

Details

### Impact This vulnerability allows an administrator unauthorized access to restricted resources.

We fixed a vulnerability in the MySQL adapter to prevent SQL injection attacks. This is a backport of CVE-2021-21024 https://helpx.adobe.com/security/products/magento/apsb21-08.html.

### Patches _Has the problem been patched? What versions should users upgrade to?_ > v20.0.9 v19.4.13

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/openmage/magento-lts
Introduced in: 0Fixed in: 19.4.13
Fixcomposer require openmage/magento-lts:^19.4.13
Packagist/openmage/magento-lts
Introduced in: 20.0.0Fixed in: 20.0.9
Fixcomposer require openmage/magento-lts:^20.0.9

References