CVE-2020-15244

In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product. The issue is patched in versions 19.4.8 and 20.0.4.
Configurations

Configuration 1

cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:*
cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:*

Information

Published : 2020-10-21 08:15

Updated : 2021-11-18 04:21


NVD link : CVE-2020-15244

Mitre link : CVE-2020-15244

Products Affected
No products.
CWE
CWE-502

Deserialization of Untrusted Data