QID 996608
Date Published: 2024-01-11
QID 996608: PHP (Composer) Security Update for magento/core (GHSA-j4fq-3fm7-wh5v)
The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.2.1 and Enterprise Edition (EE) before 1.14.2.1, when used with PHP before 5.4.24 or 5.5.8, allows remote authenticated users to execute arbitrary PHP code via the productData parameter to index.php/api/v2_soap.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-j4fq-3fm7-wh5v for updates and patch information.
Vendor References
- GHSA-j4fq-3fm7-wh5v -
github.com/advisories/GHSA-j4fq-3fm7-wh5v
CVEs related to QID 996608
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-j4fq-3fm7-wh5v | magento/core |
|