CVE-2022-24086
published 2022-02-16CVE-2022-24086: Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout…
PriorityP196critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-03-01
Exploited in the wild
EPSS
99.20%
99.9th percentile
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | commerce | < 2.3.0 | 2.3.0 |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | 2.3.3 – 2.3.6 | — |
| adobe | commerce | 2.4.0 – 2.4.2 | — |
| adobe | magento | < 2.3.0 | 2.3.0 |
| adobe | magento | <= 2.3.6 | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
| adobe | magento | 2.4.0 – 2.4.2 | — |
| adobe | magento_commerce | unspecified – 2.4.3-p1 | — |
| magento | community-edition | >= 2.3.3-p1 < 2.3.7-p3 | 2.3.7-p3 |
| magento | community-edition | >= 2.4.0 < 2.4.3-p2 | 2.4.3-p2 |
Detection & IOCsextracted from sources · hover to see the quote
url/checkout/cart/add/uenc/{{base64(BaseURL)}}%2C/product/{{product_id}}/
url/rest/default/V1/guest-carts/{entity_id}/shipping-information
url/rest/default/V1/guest-carts/{entity_id}/payment-information
command{{var this.getTemplateFilter().filter(foobar)}}{{var this.getTemplateFilter().addAfterFilterCallback(system).filter(cat$IFS/etc/passwd)}}
otherX-Magento-Tags
- →Check Point IPS signature name for this CVE is 'Adobe Commerce Command Injection (CVE-2022-24086)'; use this as a reference for IPS rule naming/tuning. ↗
- →Identify vulnerable Magento/Adobe Commerce instances via Shodan by querying for the HTTP response header 'X-Magento-Tags'.
- →Exploitation occurs during the checkout process; monitor for template injection strings (e.g., 'getTemplateFilter', 'addAfterFilterCallback') in firstname/lastname fields of shipping or billing address JSON payloads. ↗
- →Successful exploitation response contains 'root:.*:0:0:' pattern (passwd file content), which can be used as a regex match in network/proxy logs to confirm active exploitation.
- →Exploitation flow begins with a GET to the base URL to harvest a form_key (hidden field), followed by adding a product to cart, then GET /checkout, and finally POST to REST shipping/payment endpoints — monitor for this sequential pattern from a single source IP.
- ·Exploitation does not require authentication (PR:N) or user interaction (UI:N), meaning unauthenticated guest checkout flows are the attack surface. ↗
- ·Affected versions are Adobe Commerce 2.4.3-p1 and earlier, and 2.3.7-p2 and earlier; detections should be scoped to these versions. ↗
- ·This vulnerability is listed in CISA KEV with a remediation due date of 2022-03-01, indicating confirmed in-the-wild exploitation; prioritize detection on internet-facing Magento/Adobe Commerce instances. ↗
- ·Attack volume was observed to increase towards the holiday season, suggesting opportunistic mass exploitation campaigns targeting online stores. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Magento improper input validation vulnerability
ghsa·2022-02-17
CVE-2022-24086 [CRITICAL] CWE-20 Magento improper input validation vulnerability
Magento improper input validation vulnerability
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
OSV
Magento improper input validation vulnerability
osv·2022-02-17
CVE-2022-24086 [CRITICAL] Magento improper input validation vulnerability
Magento improper input validation vulnerability
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
VulnCheck
Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
vulncheck·2022·CVSS 9.8
CVE-2022-24086 [CRITICAL] CWE-20 Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.
Affected: Adobe Commerce and Magento Open Source
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.bleepingcomputer.com/news/security/emergency-magento-update-fixes-zero-day-bug-exploited-in-attacks/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://sansec.io/research/vendors-defeat-magento-security-patch-simple-check; https://www.akamai.com/blog/security-research/new-sophisticated-magento-campaign-xurum-webshell; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?da
CISA
Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
cisa·2022-02-15·CVSS 9.8
CVE-2022-24086 [CRITICAL] CWE-20 Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
Vulnerability: Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
Affected: Adobe Commerce and Magento Open Source
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-24086
Remediation Due Date: 2022-03-01
No detection rules found.
Nuclei
Adobe Commerce (Magento) - Remote Code Execution
nuclei·CVSS 9.8
CVE-2022-24086 [CRITICAL] Adobe Commerce (Magento) - Remote Code Execution
Adobe Commerce (Magento) - Remote Code Execution
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
Template:
id: CVE-2022-24086
info:
name: Adobe Commerce (Magento) - Remote Code Execution
author: daffainfo
severity: critical
description: |
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
impact: |
Attackers can execute arbitrary code on the server, poten
Bleepingcomputer
Magnet Goblin hackers use 1-day flaws to drop custom Linux malware
blogs_bleepingcomputer·2024-03-09·CVSS 9.8
[CRITICAL] Magnet Goblin hackers use 1-day flaws to drop custom Linux malware
## Magnet Goblin hackers use 1-day flaws to drop custom Linux malware
## Bill Toulas
A financially motivated hacking group named Magnet Goblin uses various 1-day vulnerabilities to breach public-facing servers and deploy custom malware on Windows and Linux systems.
1-day flaws refer to publicly disclosed vulnerabilities for which a patch has been released. Threat actors looking to exploit these flaws must do so quickly before a target can apply security updates.
Though exploits are usually not made available immediately upon a flaw's disclosure, some vulnerabilities are trivial to figure out how to leverage. Additionally, reverse-engineering the patch may reveal the underlying problem and how to exploit it.
Check Point analysts who identified Magnet Goblin report that these threat act
Checkpoint
Magnet Goblin Targets Publicly Facing Servers Using 1-Day Vulnerabilities
blogs_checkpoint·2024-03-08·CVSS 4.9
CVE-2024-21887 [MEDIUM] Magnet Goblin Targets Publicly Facing Servers Using 1-Day Vulnerabilities
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## Magnet Goblin Targets Publicly Facing Servers Using 1-Day Vulnerabilities
## Key Points
Magnet Goblin is a financially motivated threat actor that quickly adopts and leverages 1-day vuln
Wiz
Crying Out Cloud - August Newsletter | Wiz
blogs_wiz·2023-08-30·CVSS 6.5
[MEDIUM] Crying Out Cloud - August Newsletter | Wiz
Welcome back! In this edition, we bring you the latest in cloud security – noteworthy incidents, exclusive data, and crucial vulnerabilities. Let's delve in.
Editor’s note: some of you may have noticed that we accidentally resent last month’s edition (July) – this was due to a technical issue for which we apologize.
Moving on – here are our top picks of cloud security highlights!
## 🐞 High Profile Vulnerabilities
## High severity vulnerabilities in Kubernetes on Windows nodes
Three high severity Kubernetes vulnerabilities were published on August 23. All three are flaws related to insufficient sanitization that could lead to privilege escalation. Kubernetes clusters are only affected by these vulnerabilities if they include Windows nodes. The vulnerabilities were assigned CVE-2023-3676
Checkpoint
21st November– Threat Intelligence Report
blogs_checkpoint·2022-11-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] 21st November– Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 21st November– Threat Intelligence Report
For the latest discoveries in cyber research for the week of 21st November, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
US CISA has discovered nation-state threat activity affecting an American federal government entity. The attackers, who CISA estimates to be Iran-sponsored, exploited the 2021 ‘Log4Shell’ vulnerability in an unpatched server to gain initial access. Afterwards, the attackers deployed a cryptocurrency miner, harvested cred
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
2022-02-16
Published
2022-02-15
Added to CISA KEV
Exploited in the wild