PT-2020-6290 · Adobe · Magento

Published

2020-04-28

·

Updated

2024-03-06

·

CVE-2020-9582

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Magento versions 2.3.4 and earlier Magento versions 2.2.11 and earlier Magento version 1.14.4.4 and earlier Magento version 1.9.4.4 and earlier
Description The issue is related to a command injection vulnerability. It could allow a remote attacker to execute arbitrary code due to the lack of proper neutralization of special elements used in an operating system command.
Recommendations For Magento versions 2.3.4 and earlier, update to a version later than 2.3.4. For Magento versions 2.2.11 and earlier, update to a version later than 2.2.11. For Magento version 1.14.4.4 and earlier, update to a version later than 1.14.4.4. For Magento version 1.9.4.4 and earlier, update to a version later than 1.9.4.4.

Fix

Command Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2021-03988
BIT-MAGENTO-2020-9582
CVE-2020-9582
GHSA-C3M4-HXV9-4MXJ

Affected Products

Magento