8.1
CVE-2025-49555
- EPSS 0.05%
- Published 12.08.2025 18:15:29
- Last modified 15.08.2025 15:39:48
- Source psirt@adobe.com
- Teams watchlist Login
- Open Login
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in privilege escalation. A high-privileged attacker could trick a victim into executing unintended actions on a web application where the victim is authenticated, potentially allowing unauthorized access or modification of sensitive data. Exploitation of this issue requires user interaction in that a victim must visit a malicious website or click on a crafted link. Scope is changed.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Data is provided by the National Vulnerability Database (NVD)
Adobe ≫ Commerce B2b Update- Version < 1.3.3
Adobe ≫ Commerce B2b Version1.3.3 Update-
Adobe ≫ Commerce B2b Version1.3.3 Updatep1
Adobe ≫ Commerce B2b Version1.3.3 Updatep10
Adobe ≫ Commerce B2b Version1.3.3 Updatep11
Adobe ≫ Commerce B2b Version1.3.3 Updatep12
Adobe ≫ Commerce B2b Version1.3.3 Updatep13
Adobe ≫ Commerce B2b Version1.3.3 Updatep14
Adobe ≫ Commerce B2b Version1.3.3 Updatep2
Adobe ≫ Commerce B2b Version1.3.3 Updatep3
Adobe ≫ Commerce B2b Version1.3.3 Updatep4
Adobe ≫ Commerce B2b Version1.3.3 Updatep5
Adobe ≫ Commerce B2b Version1.3.3 Updatep6
Adobe ≫ Commerce B2b Version1.3.3 Updatep7
Adobe ≫ Commerce B2b Version1.3.3 Updatep8
Adobe ≫ Commerce B2b Version1.3.3 Updatep9
Adobe ≫ Commerce B2b Version1.3.4 Update-
Adobe ≫ Commerce B2b Version1.3.4 Updatep1
Adobe ≫ Commerce B2b Version1.3.4 Updatep10
Adobe ≫ Commerce B2b Version1.3.4 Updatep11
Adobe ≫ Commerce B2b Version1.3.4 Updatep12
Adobe ≫ Commerce B2b Version1.3.4 Updatep13
Adobe ≫ Commerce B2b Version1.3.4 Updatep2
Adobe ≫ Commerce B2b Version1.3.4 Updatep3
Adobe ≫ Commerce B2b Version1.3.4 Updatep4
Adobe ≫ Commerce B2b Version1.3.4 Updatep5
Adobe ≫ Commerce B2b Version1.3.4 Updatep6
Adobe ≫ Commerce B2b Version1.3.4 Updatep7
Adobe ≫ Commerce B2b Version1.3.4 Updatep8
Adobe ≫ Commerce B2b Version1.3.4 Updatep9
Adobe ≫ Commerce B2b Version1.3.5 Update-
Adobe ≫ Commerce B2b Version1.3.5 Updatep1
Adobe ≫ Commerce B2b Version1.3.5 Updatep10
Adobe ≫ Commerce B2b Version1.3.5 Updatep11
Adobe ≫ Commerce B2b Version1.3.5 Updatep2
Adobe ≫ Commerce B2b Version1.3.5 Updatep3
Adobe ≫ Commerce B2b Version1.3.5 Updatep4
Adobe ≫ Commerce B2b Version1.3.5 Updatep5
Adobe ≫ Commerce B2b Version1.3.5 Updatep6
Adobe ≫ Commerce B2b Version1.3.5 Updatep7
Adobe ≫ Commerce B2b Version1.3.5 Updatep8
Adobe ≫ Commerce B2b Version1.3.5 Updatep9
Adobe ≫ Commerce B2b Version1.4.2 Update-
Adobe ≫ Commerce B2b Version1.4.2 Updatep1
Adobe ≫ Commerce B2b Version1.4.2 Updatep2
Adobe ≫ Commerce B2b Version1.4.2 Updatep3
Adobe ≫ Commerce B2b Version1.4.2 Updatep4
Adobe ≫ Commerce B2b Version1.4.2 Updatep5
Adobe ≫ Commerce B2b Version1.4.2 Updatep6
Adobe ≫ Commerce B2b Version1.5.2 Update-
Adobe ≫ Commerce B2b Version1.5.2 Updatep1
Adobe ≫ Commerce B2b Version1.5.3 Updatealpha1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.159 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
psirt@adobe.com | 8.1 | 1.7 | 5.8 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.