PT-2020-14309 · Magento · Magento-Lts

Luke Rodgers

·

Published

2020-10-21

·

Updated

2021-11-18

·

CVE-2020-15244

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions magento-lts versions prior to 19.4.8 magento-lts versions prior to 20.0.4
Description The issue allows an admin user to generate soap credentials that can be used to trigger remote code execution (RCE) via PHP Object Injection through product attributes and a product.
Recommendations For versions prior to 19.4.8, update to version 19.4.8 or later. For versions prior to 20.0.4, update to version 20.0.4 or later.

Fix

Special Elements Injection

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15244
GHSA-JRGF-VFW2-HJ26

Affected Products

Magento-Lts