Adobe Magento是美国奥多比(Adobe)公司的一套开源的PHP电子商务系统。该系统提供权限管理、搜索引擎和支付网关等功能。Magento Open Source是Magento的开源版本。Magento Commerce是Magento的商业版本。 Magento存在SQL注入漏洞,该漏洞源于用户提供的数据没有足够的处理。攻击者可利用该漏洞向受影响的应用程序发送一个特制的请求,并在应用程序数据库中执行任意SQL命令。以下产品及版本受到影响:Magento Open Source: 2.0.0,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Adobe | Magento Commerce | unspecified ~ 2.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-24407 | 9.1 CRITICAL | Arbitrary code execution via file import functionality |
| CVE-2020-24401 | 6.5 MEDIUM | Incorrect permissions following the deletion of a user role or deactivation of a user |
| CVE-2020-24402 | 4.9 MEDIUM | Incorrect permissions in the Integrations component could lead to unauthorized deletion of |
| CVE-2020-24405 | 4.3 MEDIUM | Incorrect permissions in Inventory module could lead to unauthorized modification of inven |
| CVE-2020-24406 | 3.7 LOW | Document root path disclosure on Maintenance page |
| CVE-2020-24404 | 2.7 LOW | Incorrect permissions in Integrations component could lead to unauthorized deletion of cms |
| CVE-2020-24403 | 2.7 LOW | Incorrect permissions could lead to unauthorized modification of inventory source data via |
No comments yet