CVE-2020-9577: XSS
Published Jun 26, 2020
·Updated
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure .
Affected Software
9 affected componentsFixes available
composer/magento/project-community-edition<=2.0.2
composer/magento/community-edition<2.3.4-p2
2.3.4-p2
composer/magento/core<1.9.4.5
1.9.4.5
Magento Magento<=1.9.4.4
Magento Magento<=1.14.4.4
Magento Magento>=2.2.0<=2.2.11
Magento Magento>=2.2.0<=2.2.11
Magento Magento>=2.3.0<=2.3.4
Magento Magento>=2.3.0<=2.3.4
Event History
Jun 26, 2020
CVE Published
via MITRE·08:21 PM
Data Sourced
via MITRE·08:21 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
May 24, 2022
Advisory Published
via GitHub·05:21 PM
Data Sourced
via GitHub·05:21 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-9577?
CVE-2020-9577 is classified as a stored cross-site scripting vulnerability, which can lead to sensitive information disclosure.
2
How do I fix CVE-2020-9577?
To resolve CVE-2020-9577, upgrade to Magento version 2.3.4-p2, 1.9.4.5, or any later releases.
3
Which versions are affected by CVE-2020-9577?
CVE-2020-9577 affects Magento versions 2.3.4 and earlier, 2.2.11 and earlier, 1.14.4.4 and earlier, and 1.9.4.4 and earlier.
4
What type of vulnerability is CVE-2020-9577?
CVE-2020-9577 is a stored cross-site scripting (XSS) vulnerability.
5
What could be the impact of exploiting CVE-2020-9577?
Successful exploitation of CVE-2020-9577 could lead to sensitive information disclosure.