Learn about CVE-2020-24404 affecting Magento Commerce versions 2.4.0 and 2.3.5p1. Discover the impact, technical details, and mitigation steps for this vulnerability.
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component, allowing unauthorized deletion of cms pages via the REST API.
Understanding CVE-2020-24404
This CVE involves an incorrect permissions vulnerability in Magento Commerce that could be exploited to delete cms pages without proper authorization.
What is CVE-2020-24404?
The vulnerability in Magento Commerce versions 2.4.0 and 2.3.5p1 (and earlier) allows users with permissions to the Pages resource to delete cms pages via the REST API without proper authorization.
The Impact of CVE-2020-24404
Technical Details of CVE-2020-24404
This section provides more in-depth technical details about the vulnerability.
Vulnerability Description
The vulnerability lies in the Integrations component of Magento Commerce, allowing unauthorized deletion of cms pages through the REST API.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protect your systems from CVE-2020-24404 with these mitigation strategies.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates