CVE-2021-41231
Last modified
CVE-2021-41231 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. EPSS estimates a 1.23% chance of exploitation in the next 30 days.
Description
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. Versions 19.4.22 and 20.0.19 contain a patch for this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openmage | Magento | < 19.4.22 |
| Openmage | Magento | >= 20.0.0, < 20.0.19 |
References
- https://github.com/OpenMage/magento-lts/commit/d16fc6c5a1e66c6f0d9f82020f11702a7ddd78e4Patch, Third Party Advisory
- https://github.com/OpenMage/magento-lts/releases/tag/v19.4.22Release Notes, Third Party Advisory
- https://github.com/OpenMage/magento-lts/releases/tag/v20.0.19Release Notes, Third Party Advisory
- https://github.com/OpenMage/magento-lts/security/advisories/GHSA-h632-p764-pjqmThird Party Advisory
- https://github.com/OpenMage/magento-lts/commit/d16fc6c5a1e66c6f0d9f82020f11702a7ddd78e4Patch, Third Party Advisory
- https://github.com/OpenMage/magento-lts/releases/tag/v19.4.22Release Notes, Third Party Advisory
- https://github.com/OpenMage/magento-lts/releases/tag/v20.0.19Release Notes, Third Party Advisory
- https://github.com/OpenMage/magento-lts/security/advisories/GHSA-h632-p764-pjqmThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-41231?
How severe is CVE-2021-41231?
How do I fix CVE-2021-41231?
Are you affected by CVE-2021-41231?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
