CVE-2020-24408

MEDIUM

Magento < 2.3.4 and 2.4.0 - Unauthenticated Stored Cross-Site Scripting via File Upload

Title source: llm
STIX 2.1

Description

Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attacker to execute XSS attacks against other Magento users. This vulnerability requires a victim to browse to the uploaded file.

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0132
EPSS Percentile 80.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (4)
magento/community-edition 0 - 2.4.1Packagist
magento/magento 2.3.5 (4 CPE variants)
magento/magento 2.4.0 (2 CPE variants)
magento/magento < 2.3.4 (2 CPE variants)
Published Oct 16, 2020
Tracked Since Feb 18, 2026