AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-24408

MEDIUM · CVSS 6.1 EPSS 1.74%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-10-16 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-24408
Severity
MEDIUM
CVSS
6.1
EPSS
1.74%
Java

Original NVD Description

Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attacker to execute XSS attacks against other Magento users. This vulnerability requires a victim to browse to the uploaded file.