Backport for CVE-2021-21024 Blind SQLi from Magento 2
Critical severity
GitHub Reviewed
Published
Apr 20, 2021
in
OpenMage/magento-lts
•
Updated Feb 1, 2023
Package
Affected versions
<= 19.4.12
>= 20.0.0, <= 20.0.8
Patched versions
19.4.13
20.0.9
Description
Reviewed
Apr 21, 2021
Published by the National Vulnerability Database
Apr 21, 2021
Published to the GitHub Advisory Database
Apr 22, 2021
Last updated
Feb 1, 2023
Impact
This vulnerability allows an administrator unauthorized access to restricted resources.
We fixed a vulnerability in the MySQL adapter to prevent SQL injection attacks. This is a backport of CVE-2021-21024 https://helpx.adobe.com/security/products/magento/apsb21-08.html.
Patches
Has the problem been patched? What versions should users upgrade to?
References