Adobe Inc. update of the open platform for e-commerce organization (), which accounts for about the market for online store creation systems (Adobe became the owner of Magento in 2018). This update addresses 6 vulnerabilities, three of which are classified as critical (details have not yet been disclosed):
- CVE-2020-3716 — the potential for remote code execution via the deserialization of external data;
- CVE-2020-3718 — bypassing security mechanisms leading to arbitrary code execution on the server side;
- CVE-2020-3719 — the capability to inject SQL commands, allowing access to data in the database.
Source: opennet.ru
