First published: Thu Oct 15 2020(Updated: )
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. This vulnerability could be abused by authenticated users with administrative permissions to the System/Data and Transfer/Import components.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/magento/community-edition | <=2.4.0 | 2.4.1 |
Magento Magento | <2.3.5 | |
Magento Magento | <2.3.5 | |
Magento Magento | =2.3.5 | |
Magento Magento | =2.3.5 | |
Magento Magento | =2.3.5-p1 | |
Magento Magento | =2.3.5-p1 | |
Magento Magento | =2.4.0 | |
Magento Magento | =2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Magento vulnerability is CVE-2020-24407.
CVE-2020-24407 has a severity rating of 9.1 (critical).
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by CVE-2020-24407.
CVE-2020-24407 could result in arbitrary code execution.
To fix the vulnerability in Magento, update to version 2.4.1 or apply the provided patch.