cbcvebase.
CVE-2022-35698
published 2022-10-14

CVE-2022-35698: Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.

Affected

9 ranges
VendorProductVersion rangeFixed in
adobecommerce< 2.4.42.4.4
adobecommerce
adobecommerce
adobemagento_commerceunspecified – 2.4.5
adobemagento_open_source< 2.4.42.4.4
adobemagento_open_source
adobemagento_open_source
magentocommunity-edition2.4.3-p1 – 2.4.3-p3
magentoproject-community-edition0 – 2.0.2