
Cloud Vulnerability DB
A community-led vulnerabilities database
Magento versions 2.3.4 and earlier, 2.2.11 and earlier, 1.14.4.4 and earlier, and 1.9.4.4 and earlier were found to contain a command injection vulnerability. The vulnerability was assigned CVE-2020-9583 and was disclosed in March 2020. This security flaw affected multiple versions of Adobe's Magento Commerce and Open Source e-commerce platforms (CVE Details, Adobe Security).
The vulnerability is classified as a critical command injection flaw that does not require authentication for successful exploitation. This security issue was one of four command injection vulnerabilities discovered in Magento during this period (SecurityWeek).
Successful exploitation of this vulnerability could lead to arbitrary code execution on affected systems. The critical nature of this flaw and its ability to be exploited without authentication made it particularly dangerous for affected Magento installations (SecurityWeek).
The vulnerability was considered critical due to its potential for arbitrary code execution and the fact that it did not require authentication for exploitation. This made it particularly accessible to potential attackers (SecurityWeek).
Adobe addressed this vulnerability by releasing security updates for affected versions. The fixes were included in Magento Commerce and Magento Open Source versions 2.3.4-p2 and 2.3.5-p1, Magento Enterprise Edition 1.14.4.5, and Magento Community Edition 1.9.4.5 (SecurityWeek).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."