CVE-2024-45121
- EPSS 0.09%
- Veröffentlicht 10.10.2024 10:15:04
- Zuletzt bearbeitet 10.10.2024 21:37:08
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass...
CVE-2024-45120
- EPSS 0.07%
- Veröffentlicht 10.10.2024 10:15:04
- Zuletzt bearbeitet 12.12.2024 21:02:27
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to a security feature bypass. An attacker could exploit this vulnerability t...
CVE-2024-45119
- EPSS 0.3%
- Veröffentlicht 10.10.2024 10:15:04
- Zuletzt bearbeitet 12.12.2024 21:05:17
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can force the ap...
CVE-2024-45118
- EPSS 0.09%
- Veröffentlicht 10.10.2024 10:15:04
- Zuletzt bearbeitet 10.10.2024 21:47:00
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass...
CVE-2024-45117
- EPSS 0.22%
- Veröffentlicht 10.10.2024 10:15:04
- Zuletzt bearbeitet 10.10.2024 21:47:11
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An admin attacker could exploit this vulnerability to read files fro...
CVE-2024-45116
- EPSS 1.88%
- Veröffentlicht 10.10.2024 10:15:03
- Zuletzt bearbeitet 10.10.2024 21:47:27
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code. If an admin attacker can trick a user into clicking a specially ...
CVE-2024-45115
- EPSS 0.64%
- Veröffentlicht 10.10.2024 10:15:03
- Zuletzt bearbeitet 10.10.2024 21:51:56
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access o...