Improper Authentication in Magento Open Source - CVE-2015-3457

 

Improper Authentication in Magento Open Source - CVE-2015-3457

Published: April 30, 2015 / Updated: August 9, 2020


Vulnerability identifier: #VU40802
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3457
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote attackers to bypass authentication via the forwarded parameter.


Affected software

Magento Open Source

How to mitigate CVE-2015-3457

Install update from vendor's website.


External References

Related Security Bulletins