CVE-2024-20720
published 2024-02-15CVE-2024-20720: Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
PriorityP278critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
3.69%
88.5th percentile
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| magento | community-edition | >= 2.4.4-p1 < 2.4.4-p7 | 2.4.4-p7 |
| magento | community-edition | >= 2.4.5-p1 < 2.4.5-p6 | 2.4.5-p6 |
| magento | community-edition | >= 2.4.6-p1 < 2.4.6-p4 | 2.4.6-p4 |
| magento | project-community-edition | 0 – 2.0.2 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2024-20720 is an OS Command Injection vulnerability in Adobe Commerce (Magento) that does not require user interaction — monitor for unexpected OS command execution originating from the Magento application process ↗
- →Threat actor ScreamedJungle exploits CVE-2024-20720 on Magento e-commerce platforms to inject malicious JavaScript (Bablosoft JS) into compromised websites — hunt for unauthorized JavaScript injection in Magento storefronts
- →ScreamedJungle leverages PerfectCanvas technology alongside Bablosoft JS for pixel-perfect browser fingerprint replication — look for references to PerfectCanvas or Bablosoft JS in page source of Magento sites
- →Over 115 e-commerce sites have been impacted by ScreamedJungle's fingerprint theft campaign using CVE-2024-20720 and CVE-2024-34102 — scope incident response to include checks for Bablosoft JS injection across all Magento storefronts
- ·Affected versions are Adobe Commerce 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier — detections and hunting should be scoped to these versions ↗
- ·CVE-2024-20720 is chained with CVE-2024-34102 by ScreamedJungle — detections should account for both vulnerabilities being exploited in tandem on the same target
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
vulncheck9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Magento Open Source allows OS Command Injection
ghsa·2024-02-15
CVE-2024-20720 [HIGH] CWE-78 Magento Open Source allows OS Command Injection
Magento Open Source allows OS Command Injection
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.
OSV
Magento Open Source allows OS Command Injection
osv·2024-02-15
CVE-2024-20720 [HIGH] Magento Open Source allows OS Command Injection
Magento Open Source allows OS Command Injection
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.
VulnCheck
Adobe commerce Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulncheck·2024·CVSS 9.1
CVE-2024-20720 [CRITICAL] Adobe commerce Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Adobe commerce Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.
Affected: Adobe commerce
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://sansec.io/research/magento-xml-backdoor; https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/the-state-of-magecart-a-persistent-threat-to-e-commerce-secu
No detection rules found.
No public exploits indexed.
Threat Intel
ScreamedJungle
threat_intel·CVSS 9.1
CVE-2024-34102 [CRITICAL] ScreamedJungle
# Threat Actor: ScreamedJungle
## Description
ScreamedJungle is a threat actor that exploits vulnerabilities in outdated Magento e-commerce platforms to inject malicious JavaScript code, specifically Bablosoft JS, into compromised websites. This actor has harvested millions of browser fingerprints by leveraging vulnerabilities such as CVE-2024-34102 and CVE-2024-20720. ScreamedJungle utilizes PerfectCanvas technology to ensure pixel-perfect replication of legitimate user fingerprints. Group-IB analysts estimate that over 115 e-commerce sites have been impacted by this fingerprint theft campaign.
2024-02-15
Published
Exploited in the wild