Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-41231


OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. Versions 19.4.22 and 20.0.19 contain a patch for this issue.


Published

2023-01-27T19:15:10.197

Last Modified

2024-11-21T06:25:50.460

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-77
  • Type: Primary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openmage magento < 19.4.22 Yes
Application openmage magento < 20.0.19 Yes

References