CVE-2020-9664: Code Injection
Published Jul 22, 2020
·Updated
Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected Software
3 affected components
composer/magento/core<=1.9.4.5
Magento Magento<=1.9.4.5
Magento Magento<=1.14.4.5
Event History
Jul 22, 2020
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionWeakness
May 24, 2022
Advisory Published
via GitHub·05:24 PM
Frequently Asked Questions
1
What is the vulnerability ID for this Magento vulnerability?
The vulnerability ID for this Magento vulnerability is CVE-2020-9664.
2
Which versions of Magento are affected by this vulnerability?
Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier are affected by this vulnerability.
3
What is the severity of CVE-2020-9664?
The severity of CVE-2020-9664 is critical with a severity value of 9.8.
4
What is the potential impact of this vulnerability?
Successful exploitation of this vulnerability could lead to arbitrary code execution.
5
How can I fix CVE-2020-9664?
To fix CVE-2020-9664, you should update to a version of Magento that is not affected by this vulnerability.