CVE-2020-24404
Incorrect permissions in Integrations component could lead to unauthorized deletion of cmsPages via REST API
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 2.7EPSS 1.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
09 Nov 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component. This vulnerability could be abused by users with permissions to the Pages resource to delete cms pages via the REST API without authorization.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Affected products
Adobe · Magento CommerceWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →