CVE-2021-32758

HIGH

OpenMage Magento LTS <19.4.15, <20.0.11 - Command Injection

Title source: llm
STIX 2.1

Description

OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layout XML enabled admin users to execute arbitrary commands via block methods. The latest OpenMage Versions up from v19.4.15 and v20.0.11 have this Issue patched.

Scores

CVSS v3 7.2
EPSS 0.0036
EPSS Percentile 58.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-91
Status published
Products (2)
openmage/magento-lts 0 - 19.4.15Packagist
openmage/openmage < 19.4.15
Published Aug 27, 2021
Tracked Since Feb 18, 2026