MEDIUM · 5.0

CVE-2015-3457

Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote attackers to bypass authentication via the forwarded parameter.

Vulnerability Description

Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote attackers to bypass authentication via the forwarded parameter.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
MagentoMagento1.9.1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-3457?

CVE-2015-3457 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote attackers to bypass authentication via the forwarded parameter.

How severe is CVE-2015-3457?

CVE-2015-3457 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-3457?

Check the references section above for vendor advisories and patch information. Affected products include: Magento Magento.