CVE-2022-24086
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 99% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-20
מוצרים מושפעים
adobe: commerce; adobe: magento
קישורים
- https://helpx.adobe.com/security/products/magento/apsb22-12.html PatchRelease NotesVendor Advisory
- https://helpx.adobe.com/security/products/magento/apsb22-12.html PatchRelease NotesVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… Third Party AdvisoryUS Government Resource