An authenticated user with admin privileges can execute arbitrary code when creating a product via malicious XML layouts.
Tag: Magento
ASA-2019-00399 – Magento: Security bypass via form data injection
An authenticated user can inject form data and bypass security protections that prevent arbitrary PHP script upload.
ASA-2019-00398 – Magento: Arbitrary code execution via file upload in admin import feature
An authenticated user with admin privileges to the import feature can execute arbitrary code by uploading a malicious csv file.
ASA-2019-00397 – Magento: Arbitrary code execution through product imports and design layout update
An authenticated user with admin privileges can execute arbitrary code through combination of product import via crafted csv file and XML layout update.
ASA-2019-00396 – Magento: Arbitrary code execution through design layout update
An authenticated user with admin privileges can execute arbitrary code through a crafted XML layout update.
ASA-2019-00209 – Magento: HTML injection vulnerability due to insufficient data validation
An authenticated user can add and execute a malicious script on an HTML page through a vulnerable CLI command due to lack of data validation.
ASA-2019-00208 – Magento: Unauthorized access to wishlist via Insecure direct object reference in the application
An authenticated user can enumerate and access unauthorized wishlist via insecure direct object reference in the application.
ASA-2019-00207 – Magento: Admin credentials are logged in exception reports
Exception error reports capture administrative credentials in clear text format.