Lucene search

K
osvGoogleOSV:GHSA-MW95-GMW4-883P
HistoryMay 24, 2022 - 5:41 p.m.

Magento XML injection in the Widgets module

2022-05-2417:41:56
Google
osv.dev
9
magento
xml injection
widgets
vulnerability
arbitrary code execution
admin console.

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

36.3%

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the Widgets module. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

36.3%

Related for OSV:GHSA-MW95-GMW4-883P