#VU122243 Information disclosure in magento-lts
Published: February 3, 2026
magento-lts
OPENMAGE
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the application can expose admin URL via the X-Original-Url header. A remote attacker can obtain knowledge of the administrative URL interface and use it in further attacks against the web application (e.g. perform a brute-force attack of administrative accounts).