CVE-2015-1397
EXPLOITEDMagento CE/EE 1.9.1.0-1.14.1.0 - SQL Injection
Title source: llmDescription
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary SQL commands via the popularity[field_expr] parameter when the popularity[from] or popularity[to] parameter is set.
Exploits (5)
nomisec
WORKING POC
1 stars
by WHOISshuvam · remote-auth
https://github.com/WHOISshuvam/CVE-2015-1397
nomisec
WORKING POC
by Wytchwulf · remote
https://github.com/Wytchwulf/CVE-2015-1397-Magento-Shoplift
References (4)
Scores
EPSS
0.7151
EPSS Percentile
98.7%
Details
VulnCheck KEV
2016-01-22
CWE
CWE-89
Status
published
Products (2)
magento/magento
1.9.1.0
magento/magento
1.14.1.0
Published
Apr 29, 2015
Tracked Since
Feb 18, 2026