Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-49521


Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to a security feature bypass. A low privileged attacker could exploit this vulnerability to send crafted requests from the vulnerable server to internal systems, which could result in the bypassing of security measures such as firewalls. Exploitation of this issue does not require user interaction.


Published

2024-11-12T17:15:08.783

Last Modified

2024-11-18T18:44:32.113

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.7 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-918
  • Type: Primary
    CWE-918

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe commerce < 3.2.6 Yes
Application adobe magento < 3.2.6 Yes

References