Skip to content

CMS Editor code execution

Critical
mark-netalico published GHSA-52c6-6v3v-f3fg Jan 19, 2021

Package

No package listed

Affected versions

< 19.4.8, 20 < 20.0.4

Patched versions

> 19.4.9, 20 > 20.0.5

Description

Impact

An administrator with permission to import/export data and to edit cms pages was able to inject an executable file on the server via layout xml.

Patches

The latest OpenMage Versions up from 19.4.9 and 20.0.5 have this Issue solved

Severity

Critical

CVE ID

CVE-2020-26295

Weaknesses

No CWEs