TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2022-24086

CRITICALCISA KEV
9.8

Beschreibung

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

CVE Details

CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht2/16/2022
Zuletzt geandert10/23/2025
Quellekev
Honeypot-Sichtungen0

CISA KEV

HerstellerAdobe
ProduktCommerce and Magento Open Source
SchwachstellennameAdobe Commerce and Magento Open Source Improper Input Validation Vulnerability
KEV Aufnahmedatum2022-02-15
Behebungsfrist2022-03-01
Ransomware-NutzungUnknown

Betroffene Produkte

adobe:commerceadobe:magento

Schwachen (CWE)

CWE-20

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.