High severity7.2NVD Advisory· Published Aug 27, 2021· Updated Jun 17, 2026
CVE-2021-32759
CVE-2021-32759
Description
OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in versions prior to 19.4.15 and 20.0.13, it was possible for admin users to upload arbitrary executable files to the server. OpenMage versions 19.4.15 and 20.0.13 have a patch for this Issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openmage/magento-ltsPackagist | < 19.4.15 | 19.4.15 |
openmage/magento-ltsPackagist | >= 20.0.0, < 20.0.13 | 20.0.13 |
Affected products
3Patches
Vulnerability mechanics
References
6- github.com/OpenMage/magento-lts/releases/tag/v19.4.15nvdPatchThird Party AdvisoryWEB
- github.com/OpenMage/magento-lts/releases/tag/v20.0.13nvdPatchThird Party AdvisoryWEB
- github.com/OpenMage/magento-lts/security/advisories/GHSA-xm9f-vxmx-4m58nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-xm9f-vxmx-4m58ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-32759ghsaADVISORY
- github.com/OpenMage/magento-lts/commit/34709ac642d554aa1824892059186dd329db744bghsaWEB
News mentions
0No linked articles in our index yet.