RCE via PHP Object injection via SOAP Requests
Package
Affected versions
< 19.4.8
>= 20.0.0, < 20.0.4
Patched versions
19.4.8
20.0.4
Description
Published by the National Vulnerability Database
Oct 21, 2020
Reviewed
Oct 30, 2020
Published to the GitHub Advisory Database
Oct 30, 2020
Last updated
Feb 1, 2023
Impact
This vulnerability allows an admin user to generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product.
Patches
The latest OpenMage Versions up from 19.4.7 and 20.0.3 have this Issue solved
Credits
Credit to Luke Rodgers for reporting
References