Permissions, Privileges, and Access Controls in Magento Open Source and Adobe Commerce (formerly Magento Commerce) - CVE-2020-3718
Published: January 29, 2020
Vulnerability identifier: #VU24751
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3718
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to unspecified error, related to security restrctions. A remote attacker can bypass implemented security restrictions and execute arbitrary code on the server.
Affected software
Magento Open Source
Adobe Commerce (formerly Magento Commerce)
Adobe Commerce (formerly Magento Commerce)
How to mitigate CVE-2020-3718
Install updates from vendor's website.
Magento Open Source - addressed in versions 1.9.4.4, 2.2.11, 2.3.4
Adobe Commerce (formerly Magento Commerce) - update to 1.14.4.4
Adobe Commerce (formerly Magento Commerce) - update to 1.14.4.4