Openmage Magento-Lts vulnerabilities
22 known vulnerabilities affecting openmage/magento-lts.
Total CVEs
22
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH13MEDIUM5LOW1
Vulnerabilities
Page 2 of 2
CVE-2020-15244HIGHCVSS 7.2fixed in 19.4.8v>= 20.0.0, < 20.0.42020-10-21
CVE-2020-15244 [HIGH] CWE-74 CVE-2020-15244: In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user
In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product. The issue is patched in versions 19.4.8 and 20.0.4.
cvelistv5ghsanvdosv
CVE-2020-15151HIGHCVSS 8.0fixed in 19.4.6"v>= 20.0.0, < 20.0.22020-08-20
CVE-2020-15151 [HIGH] CWE-203 CVE-2020-15151: OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protectio
OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. This issue is related to Adobe's CVE-2020-9690. It is patched in versions 19.4.6 and 20.0.2.
cvelistv5ghsanvdosv
← Previous2 / 2