CVE-2020-24407: Arbitrary code execution via file import functionality
Published Nov 9, 2020
·Updated
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. This vulnerability could be abused by authenticated users with administrative permissions to the System/Data and Transfer/Import components.
Affected Software
10 affected componentsFixes available
composer/magento/project-community-edition<=2.0.2
composer/magento/community-edition<=2.4.0
2.4.1
Magento Magento<2.3.5
Magento Magento<2.3.5
Magento Magento=2.3.5
Magento Magento=2.3.5
Magento Magento=2.3.5-p1
Magento Magento=2.3.5-p1
Magento Magento=2.4.0
Magento Magento=2.4.0
Event History
Nov 9, 2020
CVE Published
via MITRE·12:39 AM
Data Sourced
via MITRE·12:39 AM
DescriptionSeverityWeakness
May 24, 2022
Advisory Published
via GitHub·05:33 PM
Frequently Asked Questions
1
What is the vulnerability ID of this Magento vulnerability?
The vulnerability ID of this Magento vulnerability is CVE-2020-24407.
2
What is the severity rating of CVE-2020-24407?
CVE-2020-24407 has a severity rating of 9.1 (critical).
3
Which versions of Magento are affected by CVE-2020-24407?
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by CVE-2020-24407.
4
What is the impact of CVE-2020-24407?
CVE-2020-24407 could result in arbitrary code execution.
5
How can the vulnerability in Magento be fixed?
To fix the vulnerability in Magento, update to version 2.4.1 or apply the provided patch.