cbcvebase.
CVE-2022-24086
published 2022-02-16

CVE-2022-24086: Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-03-01
Exploited in the wild
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

Affected

13 ranges
VendorProductVersion rangeFixed in
adobecommerce< 2.3.02.3.0
adobecommerce
adobecommerce
adobecommerce2.3.3 – 2.3.6
adobecommerce2.4.0 – 2.4.2
adobemagento< 2.3.02.3.0
adobemagento<= 2.3.6
adobemagento
adobemagento
adobemagento2.4.0 – 2.4.2
adobemagento_commerceunspecified – 2.4.3-p1
magentocommunity-edition>= 2.3.3-p1 < 2.3.7-p32.3.7-p3
magentocommunity-edition>= 2.4.0 < 2.4.3-p22.4.3-p2

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL