CVE-2020-3715: XSS
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/magento/coreto a version that resolves this vulnerability.Fixed in 1.9.4.4 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.2.11 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.3.4
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3715?
CVE-2020-3715 is classified as a stored cross-site scripting vulnerability which can lead to sensitive information disclosure.
Which versions of Magento are affected by CVE-2020-3715?
CVE-2020-3715 affects Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier.
How do I fix CVE-2020-3715?
To address CVE-2020-3715, upgrade to Magento versions 1.9.4.4, 2.2.11, or 2.3.4 or later.
What impact does CVE-2020-3715 have on my Magento site?
Exploitation of CVE-2020-3715 may allow attackers to execute arbitrary scripts in the context of the user's browser, potentially leading to sensitive information disclosure.
Is there a workaround for CVE-2020-3715?
There are no specific workarounds for CVE-2020-3715; updating to a patched version is recommended.