CVE-2020-24400: SQL injection allows arbitrary read from database
Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensitive information disclosure. This vulnerability could be exploited by an authenticated user with permissions to the product listing page to read data from the database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24400?
CVE-2020-24400 refers to an SQL Injection vulnerability in Magento versions 2.4.0 and 2.3.5 (and earlier) that could allow an authenticated user to access sensitive information from the database.
What is the severity of CVE-2020-24400?
The severity of CVE-2020-24400 is rated as high with a CVSS score of 7.1.
How does CVE-2020-24400 affect Magento?
CVE-2020-24400 affects Magento versions 2.4.0 and 2.3.5 (and earlier), potentially allowing an authenticated user with permissions to the product listing page to read data from the database.
How can the SQL Injection vulnerability in Magento be exploited?
The SQL Injection vulnerability in Magento can be exploited by an authenticated user with permissions to the product listing page to execute arbitrary SQL queries and retrieve sensitive information.
Is there a fix available for CVE-2020-24400?
Yes, a fix is available for CVE-2020-24400. It is recommended to update Magento to versions 2.4.1 or 2.3.6 (or later) to mitigate the vulnerability.