8.7

CVE-2023-38219

Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Payload is stored in an admin area, resulting in high confidentiality and integrity impact.

Data is provided by the National Vulnerability Database (NVD)
AdobeCommerce Version2.3.7 Update-
AdobeCommerce Version2.3.7 Updatep1
AdobeCommerce Version2.3.7 Updatep2
AdobeCommerce Version2.3.7 Updatep3
AdobeCommerce Version2.3.7 Updatep4
AdobeCommerce Version2.3.7 Updatep4-ext1
AdobeCommerce Version2.3.7 Updatep4-ext2
AdobeCommerce Version2.3.7 Updatep4-ext3
AdobeCommerce Version2.3.7 Updatep4-ext4
AdobeCommerce Version2.4.0 Update-
AdobeCommerce Version2.4.0 Updateext-1
AdobeCommerce Version2.4.0 Updateext-2
AdobeCommerce Version2.4.0 Updateext-3
AdobeCommerce Version2.4.0 Updateext-4
AdobeCommerce Version2.4.1 Update-
AdobeCommerce Version2.4.1 Updateext-1
AdobeCommerce Version2.4.1 Updateext-2
AdobeCommerce Version2.4.1 Updateext-3
AdobeCommerce Version2.4.1 Updateext-4
AdobeCommerce Version2.4.2 Update-
AdobeCommerce Version2.4.2 Updateext-1
AdobeCommerce Version2.4.2 Updateext-2
AdobeCommerce Version2.4.2 Updateext-3
AdobeCommerce Version2.4.2 Updateext-4
AdobeCommerce Version2.4.3 Update-
AdobeCommerce Version2.4.3 Updateext-1
AdobeCommerce Version2.4.3 Updateext-2
AdobeCommerce Version2.4.3 Updateext-3
AdobeCommerce Version2.4.3 Updateext-4
AdobeCommerce Version2.4.4 Update-
AdobeCommerce Version2.4.4 Updatep1
AdobeCommerce Version2.4.4 Updatep2
AdobeCommerce Version2.4.4 Updatep3
AdobeCommerce Version2.4.4 Updatep4
AdobeCommerce Version2.4.4 Updatep5
AdobeCommerce Version2.4.5 Update-
AdobeCommerce Version2.4.5 Updatep1
AdobeCommerce Version2.4.5 Updatep2
AdobeCommerce Version2.4.5 Updatep3
AdobeCommerce Version2.4.5 Updatep4
AdobeCommerce Version2.4.5 Updatep5
AdobeCommerce Version2.4.6 Update-
AdobeCommerce Version2.4.6 Updatep1
AdobeCommerce Version2.4.6 Updatep2
AdobeCommerce Version2.4.7 Updateb1
AdobeMagento Version2.4.4 Update- SwEditionopen_source
AdobeMagento Version2.4.4 Updatep1 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep2 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep3 SwEditionopen_source
AdobeMagento Version2.4.5 Update- SwEditionopen_source
AdobeMagento Version2.4.5 Updatep1 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep2 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep3 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep4 SwEditionopen_source
AdobeMagento Version2.4.6 Update- SwEditionopen_source
AdobeMagento Version2.4.6 Updatep1 SwEditionopen_source
AdobeMagento Version2.4.6 Updatep2 SwEditionopen_source
AdobeMagento Version2.4.7 Updateb1 SwEditionopen_source
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.52% 0.805
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.7 2.3 5.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
psirt@adobe.com 8.7 2.3 5.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.