Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. magento/community-edition
  4. ›
  5. GHSA-cv25-3pxr-4q7x

GHSA-cv25-3pxr-4q7x: Magento Open Source Security Advisory: Patch SUPEE-10975

May 15, 2024

Magento Commerce 1.14.4.0 and Open Source 1.9.4.0 have been enhanced with critical security updates to address multiple vulnerabilities, including remote code execution (RCE), cross-site scripting (XSS), cross-site request forgery (CSRF), and more. The following issues have been identified and remediated:

  • PRODSECBUG-1589: Stops Brute Force Requests via basic RSS authentication
  • MAG-23: M1 Credit Card Storage Capability
  • PRODSECBUG-2149: Authenticated RCE using customer import
  • PRODSECBUG-2159: API Based RCE Vulnerability
  • PRODSECBUG-2156: RCE Via Unauthorized Upload
  • PRODSECBUG-2155: Authenticated RCE using dataflow
  • PRODSECBUG-2053: Prevents XSS in Newsletter Template
  • PRODSECBUG-2142: XSS in CMS Preview
  • PRODSECBUG-1860: Admin Account XSS Attack Cessation via Filename
  • PRODSECBUG-2119: EE Patch to include names in templates
  • PRODSECBUG-2129: XSS in Google Analytics Vulnerability
  • PRODSECBUG-2019: Merchant Wishlist Security Strengthening
  • PRODSECBUG-2104: Send to a Friend Vulnerability
  • PRODSECBUG-2125: CSRF on deletion of Blocks Vulnerability
  • PRODSECBUG-2088: CSRF Vulnerability related to Customer Group Deletion
  • PRODSECBUG-2140: CSRF on deletion of Site Map
  • PRODSECBUG-2108: Outdated jQuery causing PCI scanning failures
  • MAG-12, MAG-2: Encryption Keys Stored in Plain Text
  • PRODSECBUG-2141: Unauthorized Admin Panel Bypass

References

  • github.com/FriendsOfPHP/security-advisories/blob/master/magento/magento1ee/2018-11-28.yaml
  • github.com/advisories/GHSA-cv25-3pxr-4q7x
  • github.com/magento/magento2
  • magento.com/security/patches/supee-10975
  • web.archive.org/web/20210517140123/https://magento.com/security/patches/supee-10975

Code Behaviors & Features

Detect and mitigate GHSA-cv25-3pxr-4q7x with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.9.0.0 before 1.14.4.0

Fixed versions

  • 1.14.4.0

Solution

Upgrade to version 1.14.4.0 or above.

Source file

packagist/magento/community-edition/GHSA-cv25-3pxr-4q7x.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:02 +0000.