Code injection in Magento Open Source - #VU18095

 

Code injection in Magento Open Source - #VU18095

Published: March 30, 2019


Vulnerability identifier: #VU18095
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to insufficient sanitization of user-supplied data when creating or editing newsletter or email templates. A remote authenticated user with privileges to create newsletter or email templates can inject and execute arbitrary PHP code on the system.



Affected software

Magento Open Source

Remediation

Install updates from vendor's website.

Magento Open Source - addressed in versions 2.1.17, 2.2.8, 2.3.1

External References

Related Security Bulletins