Lucene search

K
osvGoogleOSV:CVE-2020-24408
HistoryOct 16, 2020 - 3:15 p.m.

CVE-2020-24408

2020-10-1615:15:11
Google
osv.dev
9
magento
persistent xss
file upload

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

35.7%

Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attacker to execute XSS attacks against other Magento users. This vulnerability requires a victim to browse to the uploaded file.

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

35.7%