Description
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisioned under their old role after an administrator removes the role or disables the user's account.
Remediation
References
Related Vulnerabilities
Microsoft SQL Server Other Vulnerability (CVE-1999-1556)
WordPress Plugin WP Visitor Statistics (Real Time Traffic) Cross-Site Scripting (6.4)
WordPress Plugin Ecwid Ecommerce Shopping Cart PHP Object Injection (4.4.3)
WebLogic CVE-2022-21261 Vulnerability (CVE-2022-21261)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-3738)