HIGH7.5
GHSA-rr59-pjwj-6grj
Magento sql injection vulnerability
Quick fix
GHSA-rr59-pjwj-6grj — magento/community-edition: upgrade to the fixed version with the command below.
composer require magento/community-edition:^2.3.4Details
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/magento/community-edition
Introduced in:
2.3.0Fixed in: 2.3.4Fix
composer require magento/community-edition:^2.3.4Packagist/magento/community-edition
Introduced in:
0Fixed in: 2.2.11Fix
composer require magento/community-edition:^2.2.11