High severity8.0NVD Advisory· Published Aug 20, 2020· Updated Jun 17, 2026
CVE-2020-15151
CVE-2020-15151
Description
OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the fromkey protection in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. This issue is related to Adobe's CVE-2020-9690. It is patched in versions 19.4.6 and 20.0.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openmage/magento-ltsPackagist | < 19.4.6 | 19.4.6 |
openmage/magento-ltsPackagist | >= 20.0.0, < 20.0.2 | 20.0.2 |
Affected products
6- ghsa-coords2 versions
< 19.4.6+ 1 more
- (no CPE)range: < 19.4.6
- (no CPE)range: < 2.3.6
- cpe:2.3:a:openmage:openmage_long_term_support:*:*:*:*:*:*:*:*Range: <19.4.6
Patches
Vulnerability mechanics
References
5- github.com/OpenMage/magento-lts/commit/7c526bc6a6a51b57a1bab4c60f104dc36cde347anvdPatchThird Party AdvisoryWEB
- github.com/OpenMage/magento-lts/security/advisories/GHSA-crf2-xm6x-46p6nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-crf2-xm6x-46p6ghsaADVISORY
- helpx.adobe.com/security/products/magento/apsb20-47.htmlnvdRelease NotesVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-15151ghsaADVISORY
News mentions
0No linked articles in our index yet.