CVE-2021-39217

HIGH

Openmage Magento < 19.4.22 - Command Injection

Title source: rule
STIX 2.1

Description

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 and 20.0.19 contain patches for this issue.

References (4)

Core 4
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/OpenMage/magento-lts/releases/tag/v19.4.22
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/OpenMage/magento-lts/releases/tag/v20.0.19

Scores

CVSS v3 7.2
EPSS 0.0072
EPSS Percentile 72.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (2)
openmage/magento < 19.4.22
openmage/magento-lts 0 - 19.4.22Packagist
Published Jan 27, 2023
Tracked Since Feb 18, 2026