VDB
Sign up
HIGH7.5

GHSA-rr59-pjwj-6grj

Magento sql injection vulnerability

Quick fix

GHSA-rr59-pjwj-6grj — magento/community-edition: upgrade to the fixed version with the command below.

composer require magento/community-edition:^2.3.4

Details

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/magento/community-edition
Introduced in: 2.3.0Fixed in: 2.3.4
Fixcomposer require magento/community-edition:^2.3.4
Packagist/magento/community-edition
Introduced in: 0Fixed in: 2.2.11
Fixcomposer require magento/community-edition:^2.2.11
Packagist/magento/core
Introduced in: 0Fixed in: 1.9.4.4
Fixcomposer require magento/core:^1.9.4.4

References