CVE-2015-1397 is an SQL injection vulnerability in the getCsvFile function of the Mage_Adminhtml_Block_Widget_Grid class, affecting Magento Community Edition 1.9.1.0 and Enterprise Edition 1.14.1.0. This flaw allows authenticated remote administrators to execute arbitrary SQL commands by manipulating specific popularity parameters. With a CVSS score of 6.5, it presents a medium severity risk, enabling partial compromise of confidentiality, integrity, and availability with low attack complexity. The vulnerability has known exploit code available, including a Metasploit module and an ExploitDB entry, and was reportedly exploited in the wild within 24 hours of disclosure, garnering significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.9.1.0CPE matchmatch criteria | cpe:2.3:a:magento:magento:1.9.1.0:*:*:*:community:*:*:* | ||
1.14.1.0CPE matchmatch criteria | cpe:2.3:a:magento:magento:1.14.1.0:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.