{"id":"GHSA-jrgf-vfw2-hj26","summary":"RCE via PHP Object injection via SOAP Requests","details":"### Impact\nThis vulnerability allows an admin user to generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product.\n\n### Patches\nThe latest OpenMage Versions up from 19.4.7 and 20.0.3 have this Issue solved\n\n### Credits\nCredit to Luke Rodgers for reporting","aliases":["CVE-2020-15244"],"modified":"2026-01-30T00:54:20.204708Z","published":"2020-10-30T17:06:06Z","related":["CVE-2020-15244"],"database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-10-30T16:25:06Z","nvd_published_at":"2020-10-21T20:15:00Z","cwe_ids":["CWE-502","CWE-74"]},"references":[{"type":"WEB","url":"https://github.com/OpenMage/magento-lts/security/advisories/GHSA-jrgf-vfw2-hj26"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15244"},{"type":"WEB","url":"https://github.com/OpenMage/magento-lts/commit/26433d15b57978fcb7701b5f99efe8332ca8630b"},{"type":"PACKAGE","url":"https://github.com/OpenMage/magento-lts"}],"affected":[{"package":{"name":"openmage/magento-lts","ecosystem":"Packagist","purl":"pkg:composer/openmage/magento-lts"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"19.4.8"}]}],"versions":["1.9.1.1","1.9.2.0","1.9.2.1","1.9.2.2","1.9.2.3","1.9.2.4","1.9.3.0","1.9.3.1","v19.4.0","v19.4.1","v19.4.2","v19.4.3","v19.4.4","v19.4.5","v19.4.6","v19.4.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/10/GHSA-jrgf-vfw2-hj26/GHSA-jrgf-vfw2-hj26.json"}},{"package":{"name":"openmage/magento-lts","ecosystem":"Packagist","purl":"pkg:composer/openmage/magento-lts"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"20.0.0"},{"fixed":"20.0.4"}]}],"versions":["v20.0.0","v20.0.1","v20.0.2","v20.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/10/GHSA-jrgf-vfw2-hj26/GHSA-jrgf-vfw2-hj26.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"}]}