CVE-2020-24400

HIGH

Magento <2.4.0-2.3.5 - SQL Injection

Title source: llm
STIX 2.1

Description

Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensitive information disclosure. This vulnerability could be exploited by an authenticated user with permissions to the product listing page to read data from the database.

References (1)

Core 1
Core References

Scores

CVSS v3 7.1
EPSS 0.0026
EPSS Percentile 49.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Details

CWE
CWE-89
Status published
Products (4)
magento/community-edition 0 - 2.3.6Packagist
magento/magento 2.3.5 (2 CPE variants)
magento/magento 2.4.0 (2 CPE variants)
magento/magento < 2.3.5 (2 CPE variants)
Published Nov 09, 2020
Tracked Since Feb 18, 2026