Cross-Site Request Forgery Vulnerability in Adobe Commerce
CVE-2025-27189
4.3MEDIUM
Summary
Adobe Commerce is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability that can lead to a denial-of-service situation. Attackers can exploit this flaw by deceiving authenticated users into executing unintended actions through forged requests. This typically involves user interaction, such as clicking on malicious links or accessing compromised websites, potentially disrupting the availability of the service and affecting user experience.
Affected Version(s)
Adobe Commerce 0 <= 2.4.8-beta2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved