CVE-2020-9581: XSS
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9581?
CVE-2020-9581 has a high severity rating due to the potential for sensitive information disclosure through stored cross-site scripting.
How do I fix CVE-2020-9581?
To fix CVE-2020-9581, upgrade to Magento version 1.9.4.5 or any Magento 2 version that is 2.3.4-p2 or later.
Which versions of Magento are affected by CVE-2020-9581?
CVE-2020-9581 affects Magento versions 2.3.4 and earlier, 2.2.11 and earlier, and 1.14.4.4 and earlier.
What type of vulnerability is CVE-2020-9581?
CVE-2020-9581 is classified as a stored cross-site scripting (XSS) vulnerability.
What could happen if I don’t address CVE-2020-9581?
If CVE-2020-9581 is not addressed, it could lead to successful exploitation allowing attackers to disclose sensitive information.