HomeOpenmageCVE-2020-15151

CVE-2020-15151

HIGH
8.0CVSS
Published: 2020-08-20
Updated: 2024-11-21
AI Analysis

Description

OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. This issue is related to Adobe's CVE-2020-9690. It is patched in versions 19.4.6 and 20.0.2.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Attack Vector
network
Complexity
high
Privileges
none
User Action
required
Scope
changed
Confidentiality
high
Integrity
high
Availability
none
Weaknesses
CWE-203CWE-352

Metadata

Primary Vendor
OPENMAGE
Published
8/20/2020
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

openmage : openmage_long_term_supportopenmage : openmage_long_term_supportmagento : magentomagento : magento

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2020-15151 | HIGH Severity | CVEDatabase.com | CVEDatabase.com