{"id":"CVE-2021-39217","aliases":["GHSA-c9q3-r4rv-mjm7"],"url":"https://o3.security/vulnerability/CVE-2021-39217","summary":"Fix for arbitrary command execution in custom layout update through blocks","details":"OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 and 20.0.19 contain patches for this issue.","published":"2023-01-27T18:15:09.087Z","modified":"2026-08-07T16:57:36.834727Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"openmage/magento-lts","fixedVersion":"19.4.22"},{"ecosystem":"Packagist","name":"openmage/magento-lts","fixedVersion":"20.0.19"}],"fix":{"url":"https://github.com/OpenMage/magento-lts/commit/289bd4b4f53622138e3e5c2d2cef7502d780086f","label":"OpenMage/magento-lts@289bd4b"},"references":[{"type":"ADVISORY","url":"https://github.com/OpenMage/magento-lts/releases/tag/v19.4.22"},{"type":"ADVISORY","url":"https://github.com/OpenMage/magento-lts/releases/tag/v20.0.19"},{"type":"ADVISORY","url":"https://github.com/OpenMage/magento-lts/security/advisories/GHSA-c9q3-r4rv-mjm7"},{"type":"FIX","url":"https://github.com/OpenMage/magento-lts/commit/289bd4b4f53622138e3e5c2d2cef7502d780086f"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T16:57:36.834727Z"}}