openmage/magento-lts Security Advisories for 1.9.2.1 (12)
-
DataFlow upload remote code execution vulnerability
Affected version: >=20.0.0,<20.0.19|<19.4.22
Reported by:
GitHub -
Fix for authenticated remote code execution through layout update
Affected version: >=20.0.0,<20.0.19|<19.4.22
Reported by:
GitHub -
DoS vulnerability in MaliciousCode filter
Affected version: >=20.0.0,<20.0.19|<19.4.22
Reported by:
GitHub -
Fix for arbitrary file deletion in customer media allows for remote code execution
Affected version: >=20.0.0,<20.0.19|<19.4.22
Reported by:
GitHub -
Fix for arbitrary command execution in custom layout update through blocks
Affected version: >=20.0.0,<20.0.19|<19.4.22
Reported by:
GitHub -
magento-lts Reset Password not protected against well-timed CSRF
Affected version: >=20.0.0,<20.0.19|<19.4.22
Reported by:
GitHub -
Reported by:
GitHub -
Reported by:
GitHub -
Backport for CVE-2021-21024 Blind SQLi from Magento 2
Affected version: >=20.0.0,<=20.0.8|<=19.4.12
Reported by:
GitHub -
Fixes a bug in Zend Framework's Stream HTTP Wrapper
Affected version: >=20.0.0,<=20.0.8|<=19.4.12
Reported by:
GitHub -
RCE via PHP Object injection via SOAP Requests
Affected version: >=20.0.0,<20.0.4|<19.4.8
Reported by:
GitHub -
Observable Timing Discrepancy in OpenMage LTS
Affected version: >=20.0.0,<20.0.2|<19.4.6
Reported by:
GitHub