GHSA-cv25-3pxr-4q7x – magento/community-edition
Package
Manager: composer
Name: magento/community-edition
Vulnerable Version: >=1.9.0.0 <1.14.4.0
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
EPSS: N/A pctlN/A
Details
Magento Open Source Security Advisory: Patch SUPEE-10975 Magento Commerce 1.14.4.0 and Open Source 1.9.4.0 have been enhanced with critical security updates to address multiple vulnerabilities, including remote code execution (RCE), cross-site scripting (XSS), cross-site request forgery (CSRF), and more. The following issues have been identified and remediated: - PRODSECBUG-1589: Stops Brute Force Requests via basic RSS authentication - MAG-23: M1 Credit Card Storage Capability - PRODSECBUG-2149: Authenticated RCE using customer import - PRODSECBUG-2159: API Based RCE Vulnerability - PRODSECBUG-2156: RCE Via Unauthorized Upload - PRODSECBUG-2155: Authenticated RCE using dataflow - PRODSECBUG-2053: Prevents XSS in Newsletter Template - PRODSECBUG-2142: XSS in CMS Preview - PRODSECBUG-1860: Admin Account XSS Attack Cessation via Filename - PRODSECBUG-2119: EE Patch to include names in templates - PRODSECBUG-2129: XSS in Google Analytics Vulnerability - PRODSECBUG-2019: Merchant Wishlist Security Strengthening - PRODSECBUG-2104: Send to a Friend Vulnerability - PRODSECBUG-2125: CSRF on deletion of Blocks Vulnerability - PRODSECBUG-2088: CSRF Vulnerability related to Customer Group Deletion - PRODSECBUG-2140: CSRF on deletion of Site Map - PRODSECBUG-2108: Outdated jQuery causing PCI scanning failures - MAG-12, MAG-2: Encryption Keys Stored in Plain Text - PRODSECBUG-2141: Unauthorized Admin Panel Bypass ### Patching and Upgrading: Patches and upgrades are available for the following Magento versions: Magento Commerce 1.9.0.0-1.14.4.0: Apply SUPEE-10975 or upgrade to Magento Commerce 1.14.4.0. Magento Open Source 1.5.0.0-1.9.4.0: Apply SUPEE-10975 or upgrade to Magento Open Source 1.9.4.0.
Metadata
Created: 2024-05-15T22:34:06Z
Modified: 2024-05-15T22:34:06Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-cv25-3pxr-4q7x/GHSA-cv25-3pxr-4q7x.json
CWE IDs: []
Alternative ID: N/A
Finding: F188
Auto approve: 1