QID 996628
Date Published: 2024-01-15
QID 996628: PHP (Composer) Security Update for magento/community-edition (GHSA-pf6w-3pfw-fxvw)
Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensitive information disclosure. This vulnerability could be exploited by an authenticated user with permissions to the product listing page to read data from the database.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-pf6w-3pfw-fxvw for updates and patch information.
Vendor References
- GHSA-pf6w-3pfw-fxvw -
github.com/advisories/GHSA-pf6w-3pfw-fxvw
CVEs related to QID 996628
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pf6w-3pfw-fxvw | magento/community-edition |
|