ZeroHour

CVE-2020-24403

CVSS 3.1
2.7 low
EPSS
2%p75
Published
()
Modified
Description

Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data via the REST API.

Vendors
magento
Products
magento
Ecosystems
E-commerce
Weakness
CWE-285
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

In the news