vendor:
Magento
by:
tmrswrr
6.1
CVSS
HIGH
Server Side Injection
94
CWE
Product Name: Magento
Affected Version From: 2.4.2006
Affected Version To: 2.4.2006
Patch Exists: NO
Related CWE: CVE-2023-XXXX (example)
CPE: a:magento:magento:2.4.6
Platforms Tested:
2023
Magento ver. 2.4.6 – XSLT Server Side Injection
An attacker can inject malicious XSLT code through the 'XSLT Configuration' option in the 'Import Jobs' feature of Magento version 2.4.6, allowing them to execute commands on the server. This vulnerability has a potential impact on the confidentiality, integrity, and availability of the system.
Mitigation:
To mitigate this issue, users should update to the latest version of Magento and avoid processing untrusted XSLT configurations. Additionally, restricting access to the affected functionality can also help prevent exploitation.