CVE-2020-3719
29.01.2020, 19:15
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| magento | magento | 𝑥 ≤ 1.9.4.3 |
| magento | magento | 𝑥 ≤ 1.14.4.3 |
| magento | magento | 2.2.0 ≤ 𝑥 ≤ 2.2.10 |
| magento | magento | 2.2.0 ≤ 𝑥 ≤ 2.2.10 |
| magento | magento | 2.3.0 ≤ 𝑥 ≤ 2.3.3 |
| magento | magento | 2.3.0 ≤ 𝑥 ≤ 2.3.3 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| adobe | magento | 𝑥 ≤ 2.3.3 | CNA |
| adobe | magento | 𝑥 ≤ 2.2.10 | CNA |
| adobe | magento | 𝑥 ≤ 1.14.4.3 | CNA |