---
title: "CVE-2021-32759"
canonical: "https://kb.cynergy.app/space/MD/923599218/CVE-2021-32759"
format: markdown
---
**Description**

Specific versions of [Magento](https://cve.report/software/openmage/magento) from [Openmage](https://cve.report/vendor/openmage) contain the following vulnerability:

OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in versions prior to 19.4.15 and 20.0.13, it was possible for admin users to upload arbitrary executable files to the server. 

**Published On**

05/01/2022

**Updated On**

10/28/2022

**Trending**

FALSE

**CWE**

<u>[CWE-20](http://cwe.mitre.org/data/definitions/20.html)</u>

**Exploit**


**Mitigation:**

![image](media://8bad0e79-eda2-42da-bb2e-5095c075278e)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

- Update to OpenMage versions 19.4.15 and 20.0.13

**Reference**

|  |  |  |
| --- | --- | --- |
| Data Flow Sanitation Issue Fix · Advisory · OpenMage/magento-lts · GitHub | [http://github.com](http://github.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Release v19.4.15 · OpenMage/magento-lts · GitHub | [http://github.com](http://github.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Release v20.0.13 · OpenMage/magento-lts · GitHub | [http://github.com](http://github.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |