Lucene search

K
osvGoogleOSV:GHSA-C55H-7Q4J-G6RQ
HistoryMay 24, 2022 - 5:21 p.m.

Magento command injection vulnerability

2022-05-2417:21:49
Google
osv.dev
9
magento
command injection
vulnerability
arbitrary code execution
software

AI Score

7.9

Confidence

Low

EPSS

0.006

Percentile

78.7%

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

AI Score

7.9

Confidence

Low

EPSS

0.006

Percentile

78.7%