CVE-2020-24404

LOW

Magento <2.4.0, 2.3.5p1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component. This vulnerability could be abused by users with permissions to the Pages resource to delete cms pages via the REST API without authorization.

References (1)

Core 1
Core References

Scores

CVSS v3 2.7
EPSS 0.0027
EPSS Percentile 50.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-285
Status published
Products (4)
magento/community-edition 0 - 2.3.6Packagist
magento/magento 2.3.5 (4 CPE variants)
magento/magento 2.4.0 (2 CPE variants)
magento/magento < 2.3.5 (2 CPE variants)
Published Nov 09, 2020
Tracked Since Feb 18, 2026