9.1

CVE-2022-24093

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.

Data is provided by the National Vulnerability Database (NVD)
AdobeMagento Open Source Version < 2.3.7
AdobeMagento Open Source Version >= 2.4.0 < 2.4.3
AdobeMagento Open Source Version2.3.7 Updatep1
AdobeMagento Open Source Version2.3.7 Updatep2
AdobeMagento Open Source Version2.4.3 Update-
AdobeMagento Open Source Version2.4.3 Updatep1
AdobeCommerce Version < 2.3.7
AdobeCommerce Version >= 2.4.0 < 2.4.3
AdobeCommerce Version2.3.7 Updatep1
AdobeCommerce Version2.3.7 Updatep2
AdobeCommerce Version2.4.3 Update-
AdobeCommerce Version2.4.3 Updatep1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.02% 0.763
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
psirt@adobe.com 9.1 2.3 6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.