CVE-2024-41676 MEDIUM

CVE-2024-41676: Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs

Vendor Openmage
Product magento-lts
Weakness CWE-79 · XSS
Published July 29, 2024
Last update August 2, 2024

CVSS base score

4.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N

What the vulnerability does

01Description

Magento-lts is a long-term support alternative to Magento Community Edition (CE). This XSS vulnerability affects the design/header/welcome, design/header/logo_src, design/header/logo_src_small, and design/header/logo_alt system configs.They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. The problem is patched with Version 20.10.1 or higher.

Key dates

02Disclosure timeline

July 29, 2024 CVE published
August 2, 2024 Record updated

Related vulnerabilities

04Related CVE