GHSA-gp6m-fq6h-cjcx
Magento LTS vulnerable to stored XSS in admin file form
Quick fix
GHSA-gp6m-fq6h-cjcx — openmage/magento-lts: upgrade to the fixed version with the command below.
composer require openmage/magento-lts:^20.5.0Details
### Summary OpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields.
### Details `Mage_Adminhtml_Block_System_Config_Form_Field_File` does not escape filename value in certain situations. Same as: https://nvd.nist.gov/vuln/detail/CVE-2024-20717
### PoC 1. Create empty file with this filename: `<img src=x onerror=alert(1)>.crt` 2. Go to _System_ > _Configuration_ > _Sales | Payment Methonds_. 3. Click **Configure** on _PayPal Express Checkout_. 4. Choose **API Certificate** from dropdown _API Authentication Methods_. 5. Choose the XSS-file and click **Save Config**. 6. Profit, alerts "1" -> XSS. 7. Reload, alerts "1" -> Stored XSS.
### Impact Affects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Are you affected?
Enter the version of the package you're using.
Affected packages
20.0.0Fixed in: 20.5.0composer require openmage/magento-lts:^20.5.00Fixed in: 19.5.3composer require openmage/magento-lts:^19.5.3