cbcvebase.
CVE-2024-20719
published 2024-02-15

CVE-2024-20719: Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an…

critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into every admin page. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field, that could be leveraged to gain admin access.

Affected

7 ranges
VendorProductVersion rangeFixed in
adobecommerce
adobecommerce
adobecommerce
magentocommunity-edition>= 2.4.4-p1 < 2.4.4-p72.4.4-p7
magentocommunity-edition>= 2.4.5-p1 < 2.4.5-p62.4.5-p6
magentocommunity-edition>= 2.4.6-p1 < 2.4.6-p42.4.6-p4
magentoproject-community-edition0 – 2.0.2