Remote code execution in Magento Open Source and Adobe Commerce (formerly Magento Commerce) - #VU8453
Published: September 15, 2017 / Updated: November 22, 2018
Vulnerability identifier: #VU8453
CSH Severity: High
CVSS v4: 9.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: N/A
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to execute arbitrary code on the target system.
The weakness exists due to unknown error. A remote attacker can introduce malicious code when creating a new CMS Page and execute arbitrary code.
The weakness exists due to unknown error. A remote attacker can introduce malicious code when creating a new CMS Page and execute arbitrary code.
Affected software
Magento Open Source
Adobe Commerce (formerly Magento Commerce)
Adobe Commerce (formerly Magento Commerce)
Remediation
The vulnerability is addressed in the following versions:
Magento Open Source 1.9.3.6, Magento Commerce 1.14.3.6, Magento 2.0.16 and 2.1.9.
Magento Open Source 1.9.3.6, Magento Commerce 1.14.3.6, Magento 2.0.16 and 2.1.9.