CVE-2020-9665: XSS
Published Jul 22, 2020
·Updated
Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Affected Software
3 affected components
composer/magento/core<=1.9.4.5
Magento Magento<=1.9.4.5
Magento Magento<=1.14.4.5
Event History
Jul 22, 2020
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionWeakness
May 24, 2022
Advisory Published
via GitHub·05:24 PM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-9665.
2
What is the severity level of CVE-2020-9665?
The severity level of CVE-2020-9665 is medium.
3
What is the affected software?
The affected software is Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier.
4
What is the description of CVE-2020-9665?
CVE-2020-9665 is a stored cross-site scripting vulnerability in Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier, which can lead to sensitive information disclosure.
5
How can CVE-2020-9665 be exploited?
CVE-2020-9665 can be exploited by successfully conducting stored cross-site scripting attacks.
6
Is there a fix for CVE-2020-9665?
Yes, updating to the latest version of Magento can help mitigate the CVE-2020-9665 vulnerability.