Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-34253


Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution. Exploitation of this issue does not require user interaction.


Published

2022-08-16T21:15:09.973

Last Modified

2024-11-21T07:09:09.320

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Primary
    CWE-91

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe commerce < 2.3.7 Yes
Application adobe commerce < 2.4.3 Yes
Application adobe commerce 2.3.7 Yes
Application adobe commerce 2.3.7 Yes
Application adobe commerce 2.3.7 Yes
Application adobe commerce 2.3.7 Yes
Application adobe commerce 2.4.3 Yes
Application adobe commerce 2.4.3 Yes
Application adobe commerce 2.4.3 Yes
Application adobe commerce 2.4.4 Yes
Application magento magento < 2.3.7 Yes
Application magento magento < 2.4.3 Yes
Application magento magento 2.3.7 Yes
Application magento magento 2.3.7 Yes
Application magento magento 2.3.7 Yes
Application magento magento 2.3.7 Yes
Application magento magento 2.4.3 Yes
Application magento magento 2.4.3 Yes
Application magento magento 2.4.3 Yes
Application magento magento 2.4.4 Yes

References