Vulnerabilities > CVE-2020-24401 - Incorrect Authorization vulnerability in Magento

047910
CVSS 5.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
magento
CWE-863

Summary

Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisioned under their old role after an administrator removes the role or disables the user's account.

Vulnerable Configurations

Part Description Count
Application
Magento
190

Common Weakness Enumeration (CWE)