logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-20720

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-20720

Description:
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.
Last updated date:
02/16/2024

Reports

alt

ACTIVELY EXPLOITED

Type:
exploitation
Confidence:
HIGH
Date of publishing:
04/04/2024
Reference url to background

https://sansec.io/research/magento-xml-backdoor

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy