Количество 2
Количество 2
CVE-2020-15244
In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product. The issue is patched in versions 19.4.8 and 20.0.4.
GHSA-jrgf-vfw2-hj26
RCE via PHP Object injection via SOAP Requests
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-15244 In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product. The issue is patched in versions 19.4.8 and 20.0.4. | CVSS3: 8 | 1% Низкий | больше 5 лет назад | |
GHSA-jrgf-vfw2-hj26 RCE via PHP Object injection via SOAP Requests | CVSS3: 8 | 1% Низкий | больше 5 лет назад |
Уязвимостей на страницу