VDB
Sign up
MEDIUM4.8

GHSA-j49x-jjmj-9fqj

Magento XSS Vulnerability

Quick fix

GHSA-j49x-jjmj-9fqj — magento/core: upgrade to the fixed version with the command below.

composer require magento/core:^1.9.4.3

Details

In Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code via import / export functionality when creating profile action XML.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/magento/core
Introduced in: 0Fixed in: 1.9.4.3
Fixcomposer require magento/core:^1.9.4.3

References