CVE-2020-15151: Cross-Site Request Forgery (CSRF)
(updated )
OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the fromkey protection
in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. This issue is related to Adobe’s CVE-2020-9690. It is patched in versions 19.4.6 and 20.0.2.
References
Detect and mitigate CVE-2020-15151 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →