VYPR
Medium severity6.5NVD Advisory· Published Jul 29, 2020· Updated Jun 17, 2026

CVE-2020-9692

CVE-2020-9692

Description

Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
magento/community-editionPackagist
< 2.3.5-p22.3.5-p2

Affected products

9
  • Magento/Magento6 versions
    cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*+ 5 more
    • cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*range: <2.3.5
    • cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*range: <2.3.5
    • cpe:2.3:a:magento:magento:2.3.5:-:*:*:commerce:*:*:*
    • cpe:2.3:a:magento:magento:2.3.5:-:*:*:open_source:*:*:*
    • cpe:2.3:a:magento:magento:2.3.5:p1:*:*:commerce:*:*:*
    • cpe:2.3:a:magento:magento:2.3.5:p1:*:*:open_source:*:*:*
  • osv-coords2 versions
    < 2.3.5+ 1 more
    • (no CPE)range: < 2.3.5
    • (no CPE)range: < 2.3.5-p2
  • Range: 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier versions

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.