-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability centers on improper path validation in Magento's CMS WYSIWYG image handling (CWE-22). The commit referenced in GHSA/GitHub patch shows modifications to Cms module files related to image storage and folder deletion. Path traversal vulnerabilities in admin controllers handling file operations are common attack vectors for arbitrary file system access. The combination of user-controlled path inputs without proper sanitization in deletion operations would directly enable the described arbitrary code execution via file system manipulation.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| magento/community-edition | composer | < 2.3.5-p2 | 2.3.5-p2 |
| magento/project-community-edition | composer | <= 2.0.2 |
Ongoing coverage of React2Shell