CVE-2020-3715 is a stored cross-site scripting (XSS) vulnerability affecting multiple versions of Magento, including 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier. This vulnerability has a CVSS score of 6.1 (Medium), indicating it can be exploited remotely with low attack complexity, requiring user interaction, and potentially leading to sensitive information disclosure. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB), it has received limited community discussion and media coverage, with no evidence of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.9.4.3CPE matchmatch criteria | cpe:2.3:a:magento:magento:*:*:*:*:community:*:*:* | ||
<= 1.14.4.3CPE matchmatch criteria | cpe:2.3:a:magento:magento:*:*:*:*:enterprise:*:*:* | ||
>= 2.2.0, <= 2.2.10CPE matchmatch criteria | cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* | ||
>= 2.2.0, <= 2.2.10CPE matchmatch criteria | cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* | ||
>= 2.3.0, <= 2.3.3CPE matchmatch criteria | cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.