Adobe Commerce Vulnerable to Arbitrary Code Execution
CVE-2024-34109
7.2HIGH
Summary
Adobe Commerce contains an Improper Input Validation vulnerability that affects specific versions, resulting in the potential for arbitrary code execution within the context of the current user. This vulnerability allows attackers to exploit the system without requiring user interaction; however, administrative privileges are necessary for successful exploitation. Organizations using affected versions of Adobe Commerce are advised to implement the latest patches to mitigate these risks.
Affected Version(s)
Adobe Commerce 0 <= 2.4.4-p8
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved