Skip to main content

Posts

Showing posts with the label Magento upgrade

MAGENTO 2.2.1, 2.1.10 AND 2.0.17 PATCHES | SECURITY UPDATE

Magento Commerce and Open Source 2.2.1, 2.1.10 and 2.0.17 contain multiple security enhancements. Cross-Site Scripting (XSS). Local File Inclusion (LFI). Authenticated Admin user remote code execution (RCE)   . Arbitrary File Delete vulnerabilities APPSEC-1325: Stored XSS in Billing Agreements Type                  :          Cross-Site Scripting (XSS, stored) CVSSv3 Severity  :         5.5 (Medium) Known Attacks    :        None Description         :    An administrator with limited privileges can create Billing                                                   Agreements with embedded cross-site scripting elements that            ...