VDB
Sign up
MEDIUM5.4

GHSA-gp6m-fq6h-cjcx

Magento LTS vulnerable to stored XSS in admin file form

Quick fix

GHSA-gp6m-fq6h-cjcx — openmage/magento-lts: upgrade to the fixed version with the command below.

composer require openmage/magento-lts:^20.5.0

Details

### Summary OpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields.

### Details `Mage_Adminhtml_Block_System_Config_Form_Field_File` does not escape filename value in certain situations. Same as: https://nvd.nist.gov/vuln/detail/CVE-2024-20717

### PoC 1. Create empty file with this filename: `<img src=x onerror=alert(1)>.crt` 2. Go to _System_ > _Configuration_ > _Sales | Payment Methonds_. 3. Click **Configure** on _PayPal Express Checkout_. 4. Choose **API Certificate** from dropdown _API Authentication Methods_. 5. Choose the XSS-file and click **Save Config**. 6. Profit, alerts "1" -> XSS. 7. Reload, alerts "1" -> Stored XSS.

### Impact Affects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/openmage/magento-lts
Introduced in: 20.0.0Fixed in: 20.5.0
Fixcomposer require openmage/magento-lts:^20.5.0
Packagist/openmage/magento-lts
Introduced in: 0Fixed in: 19.5.3
Fixcomposer require openmage/magento-lts:^19.5.3

References