VDB
Sign up
MEDIUM4.3

GHSA-r3c9-9j5q-pwv4

magento-lts Reset Password not protected against well-timed CSRF

Quick fix

GHSA-r3c9-9j5q-pwv4 — openmage/magento-lts: upgrade to the fixed version with the command below.

composer require openmage/magento-lts:^19.4.22

Details

### Impact

Password reset form is vulnerable to CSRF between time reset password link is clicked and user submits new password.

### Patches

PR forthcoming

### Workarounds

None

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/openmage/magento-lts
Introduced in: 0Fixed in: 19.4.22
Fixcomposer require openmage/magento-lts:^19.4.22
Packagist/openmage/magento-lts
Introduced in: 20.0.0Fixed in: 20.0.19
Fixcomposer require openmage/magento-lts:^20.0.19

References