← Zuruck zu CVEs
CVE-2025-54236
CRITICALCISA KEV9.1
Beschreibung
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
CVE Details
CVSS v3.1 Bewertung9.1
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht9/9/2025
Zuletzt geandert5/5/2026
Quellekev
Honeypot-Sichtungen0
CISA KEV
HerstellerAdobe
ProduktCommerce and Magento
SchwachstellennameAdobe Commerce and Magento Improper Input Validation Vulnerability
KEV Aufnahmedatum2025-10-24
Behebungsfrist2025-11-14
Ransomware-NutzungUnknown
Betroffene Produkte
adobe:commerceadobe:commerce_b2badobe:magento
Schwachen (CWE)
CWE-20
Referenzen
https://helpx.adobe.com/security/products/magento/apsb25-88.html(psirt@adobe.com)
https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397(134c704f-9b21-4f2e-91b3-4a467353bcc0)
https://nullsecurityx.codes/cve-2025-54236-sessionreaper-unauthenticated-rce-in-magento(134c704f-9b21-4f2e-91b3-4a467353bcc0)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-54236(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.