CVE-2022-35698

Severity
5.4MEDIUM
EPSS
2.8%
top 13.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14
Latest updateOct 15

Description

Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0

Affected Packages5 packages

NVDadobe/commerce< 2.4.4+2
CVEListV5adobe/magento_commerceunspecified2.4.5+2
Packagistmagento/community-edition2.4.3-p12.4.3-p3

Patches

🔴Vulnerability Details

3
OSV
Magento Open Source allows Stored Cross-Site Scripting (Stored XSS)2022-10-15
GHSA
Magento Open Source allows Stored Cross-Site Scripting (Stored XSS)2022-10-15
CVEList
Adobe Commerce Stored XSS Arbitrary code execution2022-10-14
CVE-2022-35698 (MEDIUM CVSS 5.4) | Adobe Commerce versions 2.4.4-p1 (a | cvebase.io