Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inventory module. This vulnerability could be abused by authenticated users to modify inventory stock data without authorization.
References
Link | Resource |
---|---|
https://helpx.adobe.com/security/products/magento/apsb20-59.html | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: adobe
Published: 2020-10-15T00:00:00
Updated: 2020-11-09T00:39:43
Reserved: 2020-08-19T00:00:00
Link: CVE-2020-24405
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-11-09T01:15:12.803
Modified: 2022-10-21T18:57:24.397
Link: CVE-2020-24405
JSON object: View
Redhat Information
No data.
CWE