Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. This vulnerability could be abused by authenticated users with administrative permissions to the System/Data and Transfer/Import components.
References
Link | Resource |
---|---|
https://helpx.adobe.com/security/products/magento/apsb20-59.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-11-08 17:15
Updated : 2020-11-12 09:58
NVD link : CVE-2020-24407
Mitre link : CVE-2020-24407
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
magento
- magento