CVE-2020-9584: XSS
Published Jun 26, 2020
·Updated
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Affected Software
10 affected componentsFixes available
composer/magento/core<1.9.4.5
1.9.4.5
composer/magento/community-edition<2.2.12
2.2.12
composer/magento/community-edition>=2.3.0<2.3.4-p2
2.3.4-p2
composer/magento/project-community-edition<=2.0.2
Magento Magento<=1.9.4.4
Magento Magento<=1.14.4.4
Magento Magento>=2.2.0<=2.2.11
Magento Magento>=2.2.0<=2.2.11
Magento Magento>=2.3.0<=2.3.4
Magento Magento>=2.3.0<=2.3.4
Event History
Jun 26, 2020
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
May 24, 2022
Advisory Published
via GitHub·05:21 PM
Data Sourced
via GitHub·05:21 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this Magento vulnerability?
The vulnerability ID of this Magento vulnerability is CVE-2020-9584.
2
What is the severity level of CVE-2020-9584?
The severity level of CVE-2020-9584 is medium.
3
What is the affected software version range for CVE-2020-9584?
Magento versions 2.3.4 and earlier, 2.2.11 and earlier, 1.14.4.4 and earlier, and 1.9.4.4 and earlier are affected by this vulnerability.
4
What is the impact of CVE-2020-9584?
Successful exploitation of CVE-2020-9584 could lead to sensitive information disclosure.
5
Is there a fix available for CVE-2020-9584?
Yes, a fix is available for CVE-2020-9584. Please refer to the official Magento security advisory for more information.