First published: Wed Jul 22 2020(Updated: )
Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/core | <=1.9.4.5 | |
Magento Magento | <=1.9.4.5 | |
Magento Magento | <=1.14.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-9665.
The severity level of CVE-2020-9665 is medium.
The affected software is Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier.
CVE-2020-9665 is a stored cross-site scripting vulnerability in Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier, which can lead to sensitive information disclosure.
CVE-2020-9665 can be exploited by successfully conducting stored cross-site scripting attacks.
Yes, updating to the latest version of Magento can help mitigate the CVE-2020-9665 vulnerability.