Severity: CRITICAL (CVSS 9.8)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error vulnerability. Successful exploitation could lead to privilege escalation.
Published: 2020-06-26
Last Modified: 2026-06-17
References: