top of page
perceptive_background_267k.jpg

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a h…

Published:

19 april 2026 om 22:00:00

Alert date:

20 april 2026 om 18:01:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

Magento Long Term Support (LTS) versions prior to 20.17.0 contain a vulnerability where PHP functions like getimagesize(), file_exists(), and is_readable() can trigger deserialization when processing phar:// stream wrapper paths. The vulnerability occurs during image validation and media handling processes. Attackers can exploit this by uploading malicious phar files disguised as images and triggering these functions with phar:// paths to achieve arbitrary code execution. This affects the community-driven alternative to Magento Community Edition e-commerce platform. Version 20.17.0 patches this issue.

Technical details

Mitigation steps:

Affected products:

Magento Long Term Support (LTS)
OpenMage LTS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page