Magento

Magento

222 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 17.34%
  • Veröffentlicht 29.01.2020 19:15:13
  • Zuletzt bearbeitet 21.11.2024 05:31:37

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

  • EPSS 0.28%
  • Veröffentlicht 29.01.2020 19:15:13
  • Zuletzt bearbeitet 21.11.2024 05:31:37

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traversal vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • EPSS 8.7%
  • Veröffentlicht 29.01.2020 19:15:13
  • Zuletzt bearbeitet 21.11.2024 05:31:37

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

Exploit
  • EPSS 2.67%
  • Veröffentlicht 15.01.2020 17:15:13
  • Zuletzt bearbeitet 21.11.2024 02:35:05

The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.2.1 and Enterprise Edition (EE) before 1.14.2.1, when used with PHP before 5.4.24 or 5.5.8, allows remote authenticated users to e...

  • EPSS 0.18%
  • Veröffentlicht 06.11.2019 01:15:25
  • Zuletzt bearbeitet 21.11.2024 04:49:20

A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft malicious payload in the template Name field for Email template in the "Design Configurat...

  • EPSS 0.18%
  • Veröffentlicht 06.11.2019 01:15:25
  • Zuletzt bearbeitet 21.11.2024 04:49:22

A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code into the attribute set name when listing the products.

  • EPSS 1.11%
  • Veröffentlicht 06.11.2019 01:15:25
  • Zuletzt bearbeitet 21.11.2024 04:49:23

A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to modify store configurations can manipulate the connector api endpoint to ...

  • EPSS 0.18%
  • Veröffentlicht 06.11.2019 01:15:25
  • Zuletzt bearbeitet 21.11.2024 04:49:23

A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate downloadable link and cause an invocation of error handling that acceses user input ...

  • EPSS 0.19%
  • Veröffentlicht 06.11.2019 01:15:25
  • Zuletzt bearbeitet 21.11.2024 04:49:23

An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rendering module that gets passed to XML data processing engine without val...

  • EPSS 0.19%
  • Veröffentlicht 06.11.2019 00:15:13
  • Zuletzt bearbeitet 21.11.2024 04:49:31

In Magento prior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit product attributes can execute arbitrary code through crafted layout updates.