TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2025-54236

CRITICALCISA KEV
9.1

Beschreibung

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.

CVE Details

CVSS v3.1 Bewertung9.1
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht9/9/2025
Zuletzt geandert5/5/2026
Quellekev
Honeypot-Sichtungen0

CISA KEV

HerstellerAdobe
ProduktCommerce and Magento
SchwachstellennameAdobe Commerce and Magento Improper Input Validation Vulnerability
KEV Aufnahmedatum2025-10-24
Behebungsfrist2025-11-14
Ransomware-NutzungUnknown

Betroffene Produkte

adobe:commerceadobe:commerce_b2badobe:magento

Schwachen (CWE)

CWE-20

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.