CVE-2020-3758: XSS
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/magneto/coreto a version that resolves this vulnerability.Fixed in 1.9.4.4 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.2.11 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.3.4
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3758?
CVE-2020-3758 has a high severity level due to its potential for sensitive information disclosure via stored cross-site scripting.
How do I fix CVE-2020-3758?
To fix CVE-2020-3758, update Magento to version 1.9.4.4, 2.2.11, or 2.3.4 or later depending on your current version.
What versions of Magento are affected by CVE-2020-3758?
CVE-2020-3758 affects Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier.
What type of vulnerability is CVE-2020-3758?
CVE-2020-3758 is a stored cross-site scripting (XSS) vulnerability.
Can CVE-2020-3758 lead to data breaches?
Yes, successful exploitation of CVE-2020-3758 could lead to sensitive information disclosure, potentially resulting in data breaches.