CVE-2026-79322
גבוהה 8.6
תיאור (מקור, אנגלית)
SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id parameter to /mpblog/post/view.
מדדים
- CVSS 3.1
-
8.6 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-5/10/2026
- CWE
- CWE-89
מוצרים מושפעים
mageplaza: mageplaza blog
קישורים
- https://gist.github.com/mrtantoine/417ee9b774f022bd747211b9eadc0069 MitigationThird Party Advisory
- https://github.com/mageplaza/magento-2-blog/tree/v4.3.2 Product