cbcvebase.
CVE-2024-20720
published 2024-02-15

CVE-2024-20720: Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…

PriorityP278critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
3.69%
88.5th percentile
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.

Affected

7 ranges
VendorProductVersion rangeFixed in
adobecommerce
adobecommerce
adobecommerce
magentocommunity-edition>= 2.4.4-p1 < 2.4.4-p72.4.4-p7
magentocommunity-edition>= 2.4.5-p1 < 2.4.5-p62.4.5-p6
magentocommunity-edition>= 2.4.6-p1 < 2.4.6-p42.4.6-p4
magentoproject-community-edition0 – 2.0.2

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2024-20720 is an OS Command Injection vulnerability in Adobe Commerce (Magento) that does not require user interaction — monitor for unexpected OS command execution originating from the Magento application process
  • Threat actor ScreamedJungle exploits CVE-2024-20720 on Magento e-commerce platforms to inject malicious JavaScript (Bablosoft JS) into compromised websites — hunt for unauthorized JavaScript injection in Magento storefronts
  • ScreamedJungle leverages PerfectCanvas technology alongside Bablosoft JS for pixel-perfect browser fingerprint replication — look for references to PerfectCanvas or Bablosoft JS in page source of Magento sites
  • Over 115 e-commerce sites have been impacted by ScreamedJungle's fingerprint theft campaign using CVE-2024-20720 and CVE-2024-34102 — scope incident response to include checks for Bablosoft JS injection across all Magento storefronts
  • ·Affected versions are Adobe Commerce 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier — detections and hunting should be scoped to these versions
  • ·CVE-2024-20720 is chained with CVE-2024-34102 by ScreamedJungle — detections should account for both vulnerabilities being exploited in tandem on the same target

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
vulncheck9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.