Magento Incorrect Authorization Vulnerability - CVE-2020-9587 - Vulnerability Database

Magento Incorrect Authorization Vulnerability - CVE-2020-9587

High
Reference: CVE-2020-9587
Title: Magento Incorrect Authorization Vulnerability
Overview:

Magento versions 2.3.4 and earlier 2.2.11 and earlier (see note) 1.14.4.4 and earlier and 1.9.4.4 and earlier have an authorization bypass vulnerability. Successful exploitation could lead to potentially unauthorized product discounts.