Description
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inventory module. This vulnerability could be abused by authenticated users to modify inventory stock data without authorization.
Remediation
References
Related Vulnerabilities
WordPress Plugin cformsII Multiple Cross-Site Scripting Vulnerabilities (14.13.2)
ReviveAdserver Deserialization of Untrusted Data Vulnerability (CVE-2017-5830)
Liferay Portal Insufficiently Protected Credentials Vulnerability (CVE-2021-29043)
WordPress Plugin WP Open Graph Cross-Site Request Forgery (1.6.1)