Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-24086


Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.


Published

2022-02-16T17:15:13.307

Last Modified

2025-02-13T17:30:31.057

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe commerce < 2.3.0 Yes
Application adobe commerce ≤ 2.3.6 Yes
Application adobe commerce ≤ 2.4.2 Yes
Application adobe commerce 2.3.7 Yes
Application adobe commerce 2.3.7 Yes
Application adobe commerce 2.4.3 Yes
Application adobe commerce 2.4.3 Yes
Application magento magento < 2.3.0 Yes
Application magento magento ≤ 2.3.6 Yes
Application magento magento ≤ 2.4.2 Yes
Application magento magento 2.3.7 Yes
Application magento magento 2.3.7 Yes
Application magento magento 2.4.3 Yes
Application magento magento 2.4.3 Yes

References