GHSA-gp6m-fq6h-cjcx
Dashboard / Vulnerabilities / GHSA-gp6m-fq6h-cjcx
GHSA-gp6m-fq6h-cjcx
Summary: Magento LTS vulnerable to stored XSS in admin file form
Details: ### Summary OpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. ### Details `Mage_Adminhtml_Block_System_Config_Form_Field_File` does not escape filename value in certain situations. Same as: https://nvd.nist.gov/vuln/detail/CVE-2024-20717 ### PoC 1. Create empty file with this filename: `<img src=x onerror=alert(1)>.crt` 2. Go to _System_ > _Configuration_ > _Sales | Payment Methonds_. 3. Click **Configure** on _PayPal Express Checkout_. 4. Choose **API Certificate** from dropdown _API Authentication Methods_. 5. Choose the XSS-file and click **Save Config**. 6. Profit, alerts "1" -> XSS. 7. Reload, alerts "1" -> Stored XSS. ### Impact Affects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
References: https://github.com/OpenMage/magento-lts/security/advisories/GHSA-gp6m-fq6h-cjcx, https://nvd.nist.gov/vuln/detail/CVE-2024-20717, https://github.com/OpenMage/magento-lts
Affected packages
Package
Name: openmage/magento-lts
Purl: pkg:composer/openmage/magento-lts
Affected ranges
Type: ECOSYSTEM
Events:
