Magento

Magento

221 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 37.19%
  • Veröffentlicht 16.08.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 07:09:09

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve r...

  • EPSS 0.54%
  • Veröffentlicht 08.09.2021 17:15:09
  • Zuletzt bearbeitet 21.11.2024 05:59:51

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Information Disclosure vulnerability when uploading a modified png file to a product image. Successful exploitation could lead to the disclos...

  • EPSS 0.08%
  • Veröffentlicht 08.09.2021 17:15:09
  • Zuletzt bearbeitet 21.11.2024 05:59:52

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in the customers module. Successful exploitation could allow a low-privileged user to modify customer da...

  • EPSS 0.53%
  • Veröffentlicht 28.06.2021 14:15:11
  • Zuletzt bearbeitet 21.11.2024 05:59:53

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Violation of Secure Design Principles vulnerability in RMA PDF filename formats. Successful exploitation could allow an attacker to get unauthor...

  • EPSS 0.57%
  • Veröffentlicht 28.06.2021 14:15:11
  • Zuletzt bearbeitet 21.11.2024 05:59:53

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Path Traversal vulnerability when creating a store with child theme.Successful exploitation could lead to arbitrary file system write by an auth...

  • EPSS 0.35%
  • Veröffentlicht 28.06.2021 14:15:11
  • Zuletzt bearbeitet 21.11.2024 05:59:53

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper input validation vulnerability in the New customer WebAPI.Successful exploitation could allow an attacker to send unsolicited spam e-m...

  • EPSS 0.26%
  • Veröffentlicht 28.06.2021 14:15:10
  • Zuletzt bearbeitet 21.11.2024 05:59:51

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper Authorization vulnerability via the 'Create Customer' endpoint. Successful exploitation could lead to unauthorized modification of cus...

  • EPSS 23.86%
  • Veröffentlicht 28.06.2021 14:15:09
  • Zuletzt bearbeitet 21.11.2024 05:59:50

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mage-messages cookies. Successful exploitation could lead to arbitrary JavaScript execution by a...

  • EPSS 0.47%
  • Veröffentlicht 11.02.2021 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:47:24

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin ...

  • EPSS 9.49%
  • Veröffentlicht 11.02.2021 20:15:14
  • Zuletzt bearbeitet 21.11.2024 05:47:24

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the scheduled operation module. Successful exploitation could lead to arbitrary code execution by an authenticated attacke...