Information disclosure in magento-lts - #VU122243
Published: February 3, 2026
magento-lts
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the application can expose admin URL via the X-Original-Url header. A remote attacker can obtain knowledge of the administrative URL interface and use it in further attacks against the web application (e.g. perform a brute-force attack of administrative accounts).