openmage/magento-lts Security Advisories for v19.4.16 (6)
-
DataFlow upload remote code execution vulnerability
Affected version: >=20.0.0,<20.0.19|<19.4.22
Reported by:
GitHub -
Fix for authenticated remote code execution through layout update
Affected version: >=20.0.0,<20.0.19|<19.4.22
Reported by:
GitHub -
DoS vulnerability in MaliciousCode filter
Affected version: >=20.0.0,<20.0.19|<19.4.22
Reported by:
GitHub -
Fix for arbitrary file deletion in customer media allows for remote code execution
Affected version: >=20.0.0,<20.0.19|<19.4.22
Reported by:
GitHub -
Fix for arbitrary command execution in custom layout update through blocks
Affected version: >=20.0.0,<20.0.19|<19.4.22
Reported by:
GitHub -
magento-lts Reset Password not protected against well-timed CSRF
Affected version: >=20.0.0,<20.0.19|<19.4.22
Reported by:
GitHub