Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22247


Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An unauthenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.


Published

2023-03-27T21:15:10.727

Last Modified

2024-11-21T07:44:23.737

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-91

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe commerce < 2.4.4 Yes
Application adobe commerce 2.4.4 Yes
Application adobe commerce 2.4.4 Yes
Application adobe commerce 2.4.4 Yes
Application adobe commerce 2.4.5 Yes
Application adobe commerce 2.4.5 Yes
Application adobe magento_open_source < 2.4.4 Yes
Application adobe magento_open_source 2.4.4 Yes
Application adobe magento_open_source 2.4.4 Yes
Application adobe magento_open_source 2.4.4 Yes
Application adobe magento_open_source 2.4.5 Yes
Application adobe magento_open_source 2.4.5 Yes

References