CVE-2020-26285
21.01.2021, 14:15
OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vulnerability which enables remote code execution. In affected versions an administrator with permission to import/export data and to create widget instances was able to inject an executable file on the server. The latest OpenMage Versions up from 19.4.9 and 20.0.5 have this Issue solved
| Vendor | Product | Version |
|---|---|---|
| openmage | openmage | 𝑥 < 19.4.10 |
| openmage | openmage | 20.0.0 ≤ 𝑥 < 20.0.5 |
𝑥
= Vulnerable software versions
References