PT-2020-17702 · Adobe · Magento

Published

2020-01-29

·

Updated

2024-03-06

·

CVE-2020-3719

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Magento versions 2.3.3 and earlier Magento versions 2.2.10 and earlier Magento versions 1.14.4.3 and earlier Magento versions 1.9.4.3 and earlier
Description The issue is related to an sql injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
Recommendations For Magento versions 2.3.3 and earlier, update to a version later than 2.3.3. For Magento versions 2.2.10 and earlier, update to a version later than 2.2.10. For Magento versions 1.14.4.3 and earlier, update to a version later than 1.14.4.3. For Magento versions 1.9.4.3 and earlier, update to a version later than 1.9.4.3.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BIT-MAGENTO-2020-3719
CVE-2020-3719
GHSA-RR59-PJWJ-6GRJ

Affected Products

Magento