Skip to main content

CVE-2015-1397

CVSS Score Not Available
71.52%
HIGH RiskEPSS (99th percentile)

SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary SQL commands via the popularity[field_expr] parameter when the popularity[from] or popularity[to] parameter is set.

Published: 4/29/2015
Modified: 4/12/2025
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

71.52%HIGH Exploitation Risk
99th percentile

This vulnerability has a 71.52% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.