cbcvebase.
CVE-2024-20759
published 2024-04-10

CVE-2024-20759: Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be…

high8.1CVSS 3.1
AVNACLPRHUIRSCCHIHAN
Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Confidentiality and integrity are considered high due to having admin impact.

Affected

19 ranges
VendorProductVersion rangeFixed in
adobeadobe_commerce<= 2.4.7-beta3
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobemagento
adobemagento
adobemagento
adobemagento
magentocommunity-edition>= 2.4.4-p1 < 2.4.4-p82.4.4-p8
magentocommunity-edition>= 2.4.5-p1 < 2.4.5-p72.4.5-p7
magentocommunity-edition>= 2.4.6-p1 < 2.4.6-p52.4.6-p5
magentocommunity-edition>= 2.4.7-beta1 < 2.4.72.4.7
magentoproject-community-edition0 – 2.0.2