VDB
Sign up
HIGH7.2

GHSA-h632-p764-pjqm

DataFlow upload remote code execution vulnerability

Quick fix

GHSA-h632-p764-pjqm — openmage/magento-lts: upgrade to the fixed version with the command below.

composer require openmage/magento-lts:^19.4.22

Details

### Impact An administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/openmage/magento-lts
Introduced in: 0Fixed in: 19.4.22
Fixcomposer require openmage/magento-lts:^19.4.22
Packagist/openmage/magento-lts
Introduced in: 20.0.0Fixed in: 20.0.19
Fixcomposer require openmage/magento-lts:^20.0.19

References