RCE in Magento
CVE-2020-15244
8HIGH
What is CVE-2020-15244?
In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product. The issue is patched in versions 19.4.8 and 20.0.4.
Affected Version(s)
magento-lts < 19.4.8 < 19.4.8
magento-lts >= 20.0.0, < 20.0.4 < 20.0.0, 20.0.4
