Skip to content

Widget instances allows a hacker to inject an executable file on the server

High
mark-netalico published GHSA-hj6w-xrv3-wjj9 Jan 19, 2021

Package

No package listed

Affected versions

< 19.4.8, 20 < 20.0.4

Patched versions

> 19.4.9, 20 > 20.0.5

Description

Impact

An administrator with permission to import/export data and to create widget instances was able to inject an executable file on the server.

Patches

The latest OpenMage Versions up from 19.4.9 and 20.0.5 have this Issue solved

Severity

High

CVE ID

CVE-2020-26285

Weaknesses

No CWEs