Description
Magento-lts is a long-term support alternative to Magento Community Edition (CE). This XSS vulnerability affects the design/header/welcome, design/header/logo_src, design/header/logo_src_small, and design/header/logo_alt system configs.They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases.
But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. The problem is patched with Version 20.10.1 or higher.
Published: 2024-07-29
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-2272 Magento-lts is a long-term support alternative to Magento Community Edition (CE). This XSS vulnerability affects the design/header/welcome, design/header/logo_src, design/header/logo_src_small, and design/header/logo_alt system configs.They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. The problem is patched with Version 20.10.1 or higher.
Github GHSA Github GHSA GHSA-5vrp-638w-p8m2 Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
History

Fri, 23 Aug 2024 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Openmage
Openmage magento
CPEs cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:*
Vendors & Products Openmage
Openmage magento

Subscriptions

Openmage Magento
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T04:46:52.910Z

Reserved: 2024-07-18T15:21:47.486Z

Link: CVE-2024-41676

cve-icon Vulnrichment

Updated: 2024-08-02T04:46:52.910Z

cve-icon NVD

Status : Modified

Published: 2024-07-29T15:15:16.040

Modified: 2024-11-21T09:32:57.240

Link: CVE-2024-41676

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses