-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The provided vulnerability information indicates the RCE occurs through crafted PageBuilder templates, but none of the sources include specific code examples, commit diffs, or file paths. While the vulnerability is clearly tied to PageBuilder template processing methods, the documentation lacks technical details about the exact vulnerable functions. Security advisories and CVE descriptions mention the attack vector but don't identify specific PHP functions or classes involved. Without access to the patched code changes or Magento's internal implementation details of PageBuilder template handling, we cannot confidently name specific vulnerable functions with their full paths.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| magento/community-edition | composer | >= 2.3, < 2.3.2-p1 | 2.3.2-p1 |
Ongoing coverage of React2Shell