PT-2020-5357 · Adobe · Magento
Published
2020-06-22
·
Updated
2022-05-24
·
CVE-2020-9664
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Magento versions 1.14.4.5 and earlier
Magento versions 1.9.4.5 and earlier
Description
The issue is related to incorrect code generation management in the Magento Commerce platform, allowing a remote attacker to inject arbitrary code into a generated PHP file and execute it using specially crafted requests. This can lead to arbitrary code execution.
Recommendations
For Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier, apply the available patch SUPEE-11346 to resolve the issue.
Fix
Deserialization of Untrusted Data
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Magento