{"id":"CVE-2020-15244","details":"In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product. The issue is patched in versions 19.4.8 and 20.0.4.","aliases":["GHSA-jrgf-vfw2-hj26"],"modified":"2026-02-21T07:31:18.090158Z","published":"2020-10-21T20:15:13.443Z","related":["GHSA-jrgf-vfw2-hj26"],"references":[{"type":"ADVISORY","url":"https://github.com/OpenMage/magento-lts/commit/26433d15b57978fcb7701b5f99efe8332ca8630b"},{"type":"ADVISORY","url":"https://github.com/OpenMage/magento-lts/security/advisories/GHSA-jrgf-vfw2-hj26"},{"type":"ADVISORY","url":"https://github.com/OpenMage/magento-lts"},{"type":"FIX","url":"https://github.com/OpenMage/magento-lts/commit/26433d15b57978fcb7701b5f99efe8332ca8630b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openmage/magento-lts","events":[{"introduced":"0"},{"fixed":"26433d15b57978fcb7701b5f99efe8332ca8630b"},{"introduced":"16c8e84ddaf5d54eef1e025a241bdd5f9a60bd6f"},{"fixed":"26433d15b57978fcb7701b5f99efe8332ca8630b"}]}],"versions":["v19.4.5","v19.4.6","v19.4.7","v20.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-15244.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}