Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. This vulnerability could be abused by authenticated users with administrative permissions to the System/Data and Transfer/Import components.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published: 2020-11-09T00:39:56.269601Z

Updated: 2024-09-16T20:16:25.237Z

Reserved: 2020-08-19T00:00:00

Link: CVE-2020-24407

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-11-09T01:15:12.990

Modified: 2020-11-12T17:58:42.373

Link: CVE-2020-24407

cve-icon Redhat

No data.