Back to Database
Status published
High
CVE-2021-39217
OpenMage LTS arbitrary command execution in custom layout update through blocks
Vulnerability Description
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 and 20.0.19 contain patches for this issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-39217
Credits & Attribution
No credits recorded in the NVD database.
References
More from OpenMage
View All →CVE-2025-64174
OpenMage is vulnerable to XSS in Admin Notifications
Medium
4.6
CVE-2025-27400
Magento vulnerable to stored XSS in theme config fields
Low
2.9
CVE-2024-41676
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
4.1
CVE-2023-41879
Magento LTS's guest order "protect code" can be brute-forced too easily
High
7.5
CVE-2023-23617
OpenMage LTS has DoS vulnerability in MaliciousCode filter
Medium
4.9
Affected Vendor
OpenMage
View all reports →Affected Software
magento-lts
Vulnerable Versions:
< 19.4.22, >= 20.0.0, < 20.0.19
Timeline
Official Publish:
January 27th, 2023
Last Modified:
March 10th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H