-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability requires manipulation of shipment methods by authenticated admins. Core shipping configuration controllers (SaveCarrier) and carrier implementation classes (USPS Carrier) are prime candidates for unvalidated URL handling. Magento's shipping module architecture typically uses these components to interact with external services, making them likely SSRF vectors when user input isn't properly sanitized.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| magento/community-edition | composer | >= 2.1.0, < 2.1.18 | 2.1.18 |
| magento/community-edition | composer | >= 2.2.0, < 2.2.9 | 2.2.9 |
| magento/community-edition | composer | >= 2.3.0, < 2.3.2 | 2.3.2 |
Ongoing coverage of React2Shell