Published Apr 9, 2024.
Improper input validation (CVE-2024-20758) enabling arbitrary code execution by an authenticated administrator, plus stored cross-site scripting (CVE-2024-20759). Published with the 2.4.7 general availability release and the April 2024 patch set.
| CVE | CVSS | Type | Impact | Auth required |
|---|---|---|---|---|
| CVE-2024-20758 | 9.1 | improper-input-validation | arbitrary-code-execution | yes |
| CVE-2024-20759 | — | cross-site-scripting-stored | — | — |
Get this bulletin as JSON:
curl -s https://magento.watch/api/v1/security-bulletins/APSB24-18
magento.watch is built and maintained by Łukasz Bajsarowicz, solo, on weekends. If it has saved you a few hours, consider chipping in.
Sponsor →Łukasz takes on Magento 2 and Adobe Commerce engagements — upgrades, audits, performance, team mentoring.
Get in touch →