← Zuruck zu CVEs
CVE-2025-49550
MEDIUM4.3
Beschreibung
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access. Exploitation of this issue requires user interaction.
CVE Details
CVSS v3.1 Bewertung4.3
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht6/25/2025
Zuletzt geandert7/24/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
adobe:commerceadobe:commerce_b2badobe:magento
Schwachen (CWE)
CWE-863
Referenzen
https://helpx.adobe.com/security/products/magento/apsb25-50.html(psirt@adobe.com)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.