CVE-2020-24408
MEDIUMMagento < 2.3.4 and 2.4.0 - Unauthenticated Stored Cross-Site Scripting via File Upload
Title source: llmDescription
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attacker to execute XSS attacks against other Magento users. This vulnerability requires a victim to browse to the uploaded file.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://helpx.adobe.com/security/products/magento/apsb20-59.html
Scores
CVSS v3
6.1
EPSS
0.0132
EPSS Percentile
80.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (4)
magento/community-edition
0 - 2.4.1Packagist
magento/magento
2.3.5 (4 CPE variants)
magento/magento
2.4.0 (2 CPE variants)
magento/magento
< 2.3.4 (2 CPE variants)
Published
Oct 16, 2020
Tracked Since
Feb 18, 2026