BIT-magento-2020-24408

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/magento/BIT-magento-2020-24408.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-magento-2020-24408
Aliases
Published
2024-03-06T11:07:09.974Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attacker to execute XSS attacks against other Magento users. This vulnerability requires a victim to browse to the uploaded file.

Database specific
{
    "cpes": [
        "cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*",
        "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
        "cpe:2.3:a:magento:magento:2.3.5:-:*:*:commerce:*:*:*",
        "cpe:2.3:a:magento:magento:2.3.5:-:*:*:open_source:*:*:*",
        "cpe:2.3:a:magento:magento:2.3.5:p1:*:*:commerce:*:*:*",
        "cpe:2.3:a:magento:magento:2.3.5:p1:*:*:open_source:*:*:*",
        "cpe:2.3:a:magento:magento:2.4.0:*:*:*:commerce:*:*:*",
        "cpe:2.3:a:magento:magento:2.4.0:*:*:*:open_source:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / magento

Package

Name
magento
Purl
pkg:bitnami/magento

Severity

  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.4
Type
SEMVER
Events
Introduced
2.3.5
Last affected
2.3.5
Introduced
2.3.5-p1
Last affected
2.3.5-p1
Introduced
2.4.0
Last affected
2.4.0