cbcvebase.
CVE-2023-22249
published 2023-03-27

CVE-2023-22249: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be…

medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

Affected

8 ranges
VendorProductVersion rangeFixed in
adobecommerce< 2.4.42.4.4
adobecommerce
adobecommerce
adobemagento_commerceunspecified – 2.4.5-p1
adobemagento_open_source< 2.4.42.4.4
adobemagento_open_source
adobemagento_open_source
magentocommunity-edition2.4.4-p1 – 2.4.4-p2