Cross-site Request Forgery (CSRF) Affecting openmage/magento-lts package, versions <19.4.6 >=20.0.0, <20.0.2
Threat Intelligence
EPSS
0.14% (51st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PHP-OPENMAGEMAGENTOLTS-607905
- published 20 Aug 2020
- disclosed 20 Aug 2020
- credit Unknown
Introduced: 20 Aug 2020
CVE-2020-15151 Open this link in a new tabHow to fix?
Upgrade openmage/magento-lts
to version 19.4.6, 20.0.2 or higher.
Overview
openmage/magento-lts is a This repository is the home of an unofficial community-driven project.
Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF). This vulnerability allows to circumvent the formkey protection
in the Admin Interface and increases the attack surface for Cross Site Request Forgery
attacks
References
CVSS Scores
version 3.1