Skip to content

Layout XML RCE Vulnerability

High
mark-netalico published GHSA-99m6-r53j-4hh2 Jan 19, 2021

Package

No package listed

Affected versions

< 19.4.8, 20 < 20.0.4

Patched versions

> 19.4.9, 20 > 20.0.5

Description

Impact

This vulnerability allows an administrator with permission to update product data to be able to store an executable file on the server and load it via layout xml.

Patches

The latest OpenMage Versions up from 19.4.9 and 20.0.5 have this Issue solved

Severity

High

CVE ID

CVE-2020-26252

Weaknesses

No CWEs