CVE-2020-24408

CVE-2020-24408

Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attacker to execute XSS attacks against other Magento users. This vulnerability requires a victim to browse to the uploaded file.

Source: CVE-2020-24408

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다