Vulnerabilities > CVE-2020-24401 - Incorrect Authorization vulnerability in Magento

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
magento
CWE-863

Summary

Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisioned under their old role after an administrator removes the role or disables the user's account.

Vulnerable Configurations

Part Description Count
Application
Magento
102

Common Weakness Enumeration (CWE)