But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. The problem is patched with Version 20.10.1 or higher.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2272 | Magento-lts is a long-term support alternative to Magento Community Edition (CE). This XSS vulnerability affects the design/header/welcome, design/header/logo_src, design/header/logo_src_small, and design/header/logo_alt system configs.They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. The problem is patched with Version 20.10.1 or higher. |
Github GHSA |
GHSA-5vrp-638w-p8m2 | Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs |
Fri, 23 Aug 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openmage
Openmage magento |
|
| CPEs | cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:* | |
| Vendors & Products |
Openmage
Openmage magento |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T04:46:52.910Z
Reserved: 2024-07-18T15:21:47.486Z
Link: CVE-2024-41676
Updated: 2024-08-02T04:46:52.910Z
Status : Modified
Published: 2024-07-29T15:15:16.040
Modified: 2026-06-17T07:48:01.773
Link: CVE-2024-41676
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD
Github GHSA