Lucene search

K
osvGoogleOSV:CVE-2020-24405
HistoryNov 09, 2020 - 1:15 a.m.

CVE-2020-24405

2020-11-0901:15:12
Google
osv.dev
16
magento
incorrect permissions
vulnerability
inventory module
unauthorized modification

AI Score

5.8

Confidence

Low

EPSS

0.001

Percentile

38.6%

Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inventory module. This vulnerability could be abused by authenticated users to modify inventory stock data without authorization.

AI Score

5.8

Confidence

Low

EPSS

0.001

Percentile

38.6%