CVE-2020-24402

MEDIUM

Magento <2.4.0, 2.3.5p1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability in the Integrations component. This vulnerability could be abused by authenticated users with permissions to the Resource Access API to delete customer details via the REST API without authorization.

References (1)

Core 1
Core References

Scores

CVSS v3 4.9
EPSS 0.0019
EPSS Percentile 40.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-276
Status published
Products (5)
magento/community-edition 0 - 2.3.6Packagist
magento/magento 2.3.5 (4 CPE variants)
magento/magento 2.4.0 (2 CPE variants)
magento/magento < 2.3.5 (2 CPE variants)
magento/project-community-edition 0Packagist
Published Nov 09, 2020
Tracked Since Feb 18, 2026