CVE-2020-9691: XSS
Published Jul 29, 2020
·Updated
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected Software
8 affected componentsFixes available
composer/magento/project-community-edition<=2.0.2
composer/magento/community-edition<2.3.5-p2
2.3.5-p2
Magento Magento<2.3.5
Magento Magento<2.3.5
Magento Magento=2.3.5
Magento Magento=2.3.5
Magento Magento=2.3.5-p1
Magento Magento=2.3.5-p1
Remediation
Event History
Jul 29, 2020
CVE Published
via MITRE·12:20 PM
Data Sourced
via MITRE·12:20 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 24, 2022
Advisory Published
via GitHub·05:24 PM
Data Sourced
via GitHub·05:24 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-9691?
CVE-2020-9691 is a dom-based cross-site scripting vulnerability in Magento versions 2.3.5-p1 and earlier.
2
How severe is CVE-2020-9691?
CVE-2020-9691 has a severity rating of 9.6, which is considered critical.
3
How does CVE-2020-9691 affect Magento?
CVE-2020-9691 affects Magento versions 2.3.5-p1 and earlier, potentially allowing arbitrary code execution.
4
What is the fix for CVE-2020-9691?
To fix CVE-2020-9691, update Magento to a version later than 2.3.5-p1.
5
Where can I find more information about CVE-2020-9691?
You can find more information about CVE-2020-9691 at the following link: [CVE-2020-9691](https://helpx.adobe.com/security/products/magento/apsb20-47.html).