Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. magento/project-community-edition
  4. ›
  5. CVE-2020-24407

CVE-2020-24407: Magento 2 Community Edition RCE via Unsafe File Upload

May 24, 2022 (updated February 10, 2025)

Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. This vulnerability could be abused by authenticated users with administrative permissions to the System/Data and Transfer/Import components.

References

  • github.com/advisories/GHSA-7pxg-6p87-8c9v
  • github.com/magento/magento2
  • helpx.adobe.com/security/products/magento/apsb20-59.html
  • nvd.nist.gov/vuln/detail/CVE-2020-24407

Code Behaviors & Features

Detect and mitigate CVE-2020-24407 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 2.0.2

Solution

Unfortunately, there is no solution available yet.

Impact 9.1 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-434: Unrestricted Upload of File with Dangerous Type

Source file

packagist/magento/project-community-edition/CVE-2020-24407.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:11 +0000.