漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Magento Commerce XML Injection Could Lead To Arbitrary Code Execution
Vulnerability Description
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the product layout updates. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.
CVSS Information
N/A
Vulnerability Type
XML注入(XPath盲注)
Vulnerability Title
Magento Commerce 和 Magento Open Source editions 安全漏洞
Vulnerability Description
Magento Commerce 和 Magento Open Source editions 中存在安全漏洞,成功利用该漏洞可导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A