Skip to main content
CRITICAL

CVE-2024-20720

CVSS v3

9.1

CRITICAL

EPSS Score

8.4 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.

Technical details

Published
2024-02-15

Frequently asked questions

What is CVE-2024-20720?

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.

Is CVE-2024-20720 actively exploited?

Active exploitation of CVE-2024-20720 has not been confirmed. The EPSS score is 8.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2024-20720?

CVE-2024-20720 has a CVSS v3 base score of 9.1 (CRITICAL severity).

Is CVE-2024-20720 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key