CVE-2024-41676
CVSS V2 None
CVSS V3 None
Description
Magento-lts is a long-term support alternative to Magento Community Edition (CE). This XSS vulnerability affects the design/header/welcome, design/header/logo_src, design/header/logo_src_small, and design/header/logo_alt system configs.They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases.
But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. The problem is patched with Version 20.10.1 or higher.
Overview
- CVE ID
- CVE-2024-41676
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-07-29T14:46:26.806Z
- Last Modified Date
- 2024-07-29T15:41:08.994Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/OpenMage/magento-lts/security/advisories/GHSA-5vrp-638w-p8m2 | x_refsource_CONFIRM |
https://github.com/OpenMage/magento-lts/commit/484cf8afc550e98bbf2c03fbb29a8450a32e7948 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-41676 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-41676 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-07-30 13:14:47 | Added to TrackCVE |