PT-2020-4584 · Adobe · Magento
Published
2020-10-15
·
Updated
2024-03-06
·
CVE-2020-24408
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Magento versions 2.4.0 and 2.3.5p1 (and earlier)
Description
The issue is related to a persistent XSS vulnerability in the file upload component, allowing users to upload malicious JavaScript. This could be exploited by an unauthenticated attacker to execute XSS attacks against other Magento users, requiring a victim to browse to the uploaded file. The vulnerability exists due to insufficient cleaning of user-provided data, which may allow a remote attacker to execute malicious JavaScript code using specially crafted HTTP requests.
Recommendations
For Magento versions 2.4.0 and 2.3.5p1 (and earlier), consider disabling the file upload component until a patch is available to prevent the upload of malicious JavaScript files. Restrict access to uploaded files to minimize the risk of exploitation. Avoid using the file upload feature in the affected versions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Magento