CVE-2015-1399: Code Injection
PHP remote file inclusion vulnerability in the fetchView function in the MageCoreBlockTemplateZend class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary PHP code via a URL in unspecified vectors involving the setScriptPath function. NOTE: it is not clear whether this issue crosses privilege boundaries, since administrators might already have privileges to include arbitrary files.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1399?
CVE-2015-1399 has been assigned a high severity level due to its potential for remote code execution.
How do I fix CVE-2015-1399?
To fix CVE-2015-1399, it is recommended to update Magento to the latest version that addresses this vulnerability.
What versions of Magento are affected by CVE-2015-1399?
CVE-2015-1399 affects Magento Community Edition 1.9.1.0 and Enterprise Edition 1.14.1.0.
What types of attacks can be executed due to CVE-2015-1399?
CVE-2015-1399 allows attackers to execute arbitrary PHP code remotely, leading to potential full system compromise.
Who can exploit CVE-2015-1399?
CVE-2015-1399 can be exploited by remote administrators with access to the vulnerable Magento installation.