First published: Wed Jul 29 2020(Updated: )
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/community-edition | <2.3.5-p2 | 2.3.5-p2 |
Magento Magento | <2.3.5 | |
Magento Magento | <2.3.5 | |
Magento Magento | =2.3.5 | |
Magento Magento | =2.3.5 | |
Magento Magento | =2.3.5-p1 | |
Magento Magento | =2.3.5-p1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9691 is a dom-based cross-site scripting vulnerability in Magento versions 2.3.5-p1 and earlier.
CVE-2020-9691 has a severity rating of 9.6, which is considered critical.
CVE-2020-9691 affects Magento versions 2.3.5-p1 and earlier, potentially allowing arbitrary code execution.
To fix CVE-2020-9691, update Magento to a version later than 2.3.5-p1.
You can find more information about CVE-2020-9691 at the following link: [CVE-2020-9691](https://helpx.adobe.com/security/products/magento/apsb20-47.html).