CVE-2020-24403

LOW

Magento <2.4.0, 2.3.5p1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data via the REST API.

References (1)

Core 1
Core References

Scores

CVSS v3 2.7
EPSS 0.0019
EPSS Percentile 40.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-285
Status published
Products (5)
magento/community-edition 0 - 2.3.6Packagist
magento/magento 2.3.5 (4 CPE variants)
magento/magento 2.4.0 (2 CPE variants)
magento/magento < 2.3.5 (2 CPE variants)
magento/project-community-edition 0Packagist
Published Nov 09, 2020
Tracked Since Feb 18, 2026