Skip to content

Layout XML Arbitrary Code Fix

High
mark-netalico published GHSA-26rr-v2j2-25fh Aug 27, 2021

Package

No package listed

Affected versions

< 19.4.13, 20 < 20.0.10

Patched versions

> 19.4.13, 20 > 20.0.11

Description

Impact

Layout XML enabled admin users to execute arbitrary commands via block methods.

Patches

The latest OpenMage Versions up from v19.4.13 and v20.0.11 have this Issue solved

Severity

High

CVE ID

CVE-2021-32758

Weaknesses

No CWEs