Lucene search

K
osvGoogleOSV:CVE-2020-24403
HistoryNov 09, 2020 - 1:15 a.m.

CVE-2020-24403

2020-11-0901:15:12
Google
osv.dev
10
magento
vulnerability
user permissions
inventory component
rest api

AI Score

5.4

Confidence

Low

EPSS

0.001

Percentile

38.6%

Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data via the REST API.

AI Score

5.4

Confidence

Low

EPSS

0.001

Percentile

38.6%