PT-2020-5357 · Adobe · Magento

Published

2020-06-22

·

Updated

2022-05-24

·

CVE-2020-9664

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Magento versions 1.14.4.5 and earlier Magento versions 1.9.4.5 and earlier
Description The issue is related to incorrect code generation management in the Magento Commerce platform, allowing a remote attacker to inject arbitrary code into a generated PHP file and execute it using specially crafted requests. This can lead to arbitrary code execution.
Recommendations For Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier, apply the available patch SUPEE-11346 to resolve the issue.

Fix

Deserialization of Untrusted Data

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00225
CVE-2020-9664
GHSA-337C-3RCH-Q35J

Affected Products

Magento