Adobe (Magento) Update
2822Warning Date
Severity Level
Warning Number
Target Sector
23 June, 2020
● Critical
2020-1378
All
Description:
Adobe has released security update to address two vulnerabilities in the following versions of Magento:
- Magento Commerce 1
- 1.14.4.5 and earlier versions
- Magento Open Source 1
- 1.9.4.5 and earlier versions
Support for Magento Commerce 1.14 and Magento Open Source 1 is ending in June 2020.
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Cross-site scripting (XSS) attack which may lead to sensitive information disclosure.
- Arbitrary code execution.
Best practice and Recommendations:
The CERT team encourages users to review Adobe security advisory and apply the necessary update: