Adobe Commerce Vulnerable to OS Command Injection Attacks

CVE-2024-20720
9.1CRITICAL

Key Information

Vendor
Adobe
Status
Adobe Commerce
Vendor
CVE Published:
15 February 2024

Badges

๐Ÿ˜„ Trended๐Ÿ‘พ Exploit Exists๐Ÿ“ฐ News Worthy

Summary

The vulnerability identified as CVE-2024-20720 affects Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6, and earlier, allowing for OS Command Injection attacks that could lead to arbitrary code execution. It does not require user interaction for exploitation, and threat actors have been observed using this vulnerability to deploy a persistent backdoor on e-commerce websites. Attackers have combined the Magento layout parser with the beberlei/assert package to execute system commands, allowing for the injection of a fake Stripe payment skimmer to capture and send data to another compromised Magento store. Adobe has released security updates to address this vulnerability, and administrators are urged to update their websites and scan for any indicators of compromise.

Affected Version(s)

Adobe Commerce <= 2.4.4-p6

News Articles

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability started trending.

  • ๐Ÿ‘พ

    Exploit exists.

  • First article discovered by null

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database0 Proof of Concept(s)5 News Article(s)
.