CVE-2020-24407

CRITICAL

Magento <2.4.0-2.3.5p1 - RCE

Title source: llm
STIX 2.1

Description

Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. This vulnerability could be abused by authenticated users with administrative permissions to the System/Data and Transfer/Import components.

References (1)

Core 1
Core References

Scores

CVSS v3 9.1
EPSS 0.0372
EPSS Percentile 88.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (5)
magento/community-edition 0 - 2.4.1Packagist
magento/magento 2.3.5 (4 CPE variants)
magento/magento 2.4.0 (2 CPE variants)
magento/magento < 2.3.5 (2 CPE variants)
magento/project-community-edition 0Packagist
Published Nov 09, 2020
Tracked Since Feb 18, 2026