PT-2020-5060 · Adobe · Magento

Published

2020-07-28

·

Updated

2024-03-06

·

CVE-2020-9692

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Magento versions 2.3.5-p1 and earlier
Description The issue is related to a security mitigation bypass vulnerability in the authorization mechanism of the Magento platform. Successful exploitation could lead to arbitrary code execution, allowing a remote attacker to execute code in the context of the current user.
Recommendations For Magento versions 2.3.5-p1 and earlier, update to a version that includes the security mitigation bypass vulnerability fix to prevent arbitrary code execution.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2020-05649
BIT-MAGENTO-2020-9692
CVE-2020-9692
GHSA-VQG7-8V6X-54RQ

Affected Products

Magento