QID 13250
Date Published: 2021-04-15
QID 13250: Magento Commerce Remote Code Execution Vulnerability
Magento is PHP based e-commerce platform.
Magento Commerce has a remote code execution vulnerability
Affected Versions:
Magento Commerce prior to 1.14.4.2
Magento 2.1 prior to 2.1.18
Magento 2.2 prior to 2.2.9
Magento 2.3 prior to 2.3.2
QID Detection Logic:
This QID checks for vulnerable version of Magento on system
An authenticated user with admin privileges to create sitemaps can execute arbitrary PHP code by creating a malicious sitemap file.
Solution
The vendor has released a fix in PRODSECBUG-2351 to remediate this vulnerability.
Vendor References
CVEs related to QID 13250
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Magento |
|