Layout XML Arbitrary Code Fix
Package
Affected versions
< 19.4.15
>= 20.0.0, < 20.0.13
Patched versions
19.4.15
20.0.13
Description
Published by the National Vulnerability Database
Aug 27, 2021
Reviewed
Aug 30, 2021
Published to the GitHub Advisory Database
Aug 30, 2021
Last updated
Feb 1, 2023
Impact
Layout XML enabled admin users to execute arbitrary commands via block methods.
References