PKSA-br3d-5r49-ycpt Security Advisory
-
[HIGH] Magento has incorrect authorization issue that leads to arbitrary file system read
PKSA-br3d-5r49-ycpt CVE-2025-49556 GHSA-7hrj-3c9x-xv5h
Affected package: magento/community-edition
Affected version: =2.4.8|=2.4.7|=2.4.6|=2.4.5|<2.4.5-p14|>=2.4.6-p1,<2.4.6-p12|>=2.4.7-beta1,<2.4.7-p7|>=2.4.8-beta1,<2.4.8-p2|>=2.4.9-alpha1,<2.4.9-alpha2
Reported by:
GitHub