CVE-2020-3719: SQL Injection
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/magento/coreto a version that resolves this vulnerability.Fixed in 1.9.4.4 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.2.11 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.3.4
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3719?
CVE-2020-3719 is classified as an SQL injection vulnerability that could lead to sensitive information disclosure.
How do I fix CVE-2020-3719?
To fix CVE-2020-3719, update your Magento installation to version 1.9.4.4, 2.2.11, or 2.3.4.
Which versions of Magento are affected by CVE-2020-3719?
CVE-2020-3719 affects Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier.
Can CVE-2020-3719 lead to data breaches?
Yes, successful exploitation of CVE-2020-3719 could potentially lead to sensitive information disclosure, increasing the risk of data breaches.
What type of vulnerability is CVE-2020-3719?
CVE-2020-3719 is an SQL injection vulnerability.