CVE-2020-15244

In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product. The issue is patched in versions 19.4.8 and 20.0.4.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:*
cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:*

History

18 Nov 2021, 16:21

Type Values Removed Values Added
CWE CWE-74

Information

Published : 2020-10-21 20:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-15244

Mitre link : CVE-2020-15244

CVE.ORG link : CVE-2020-15244


JSON object : View

Products Affected

openmage

  • magento
CWE
CWE-502

Deserialization of Untrusted Data

CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')