cbcvebase.
CVE-2024-39403
published 2024-08-14

CVE-2024-39403: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be…

high7.6CVSS 3.1
AVNACLPRLUIRSCCHILAN
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Confidentiality impact is high due to the attacker being able to exfiltrate sensitive information.

Affected

16 ranges
VendorProductVersion rangeFixed in
adobeadobe_commerce<= 2.4.4-p9
adobecommerce<= 2.4.3
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobemagento<= 2.4.3
adobemagento
adobemagento
adobemagento
adobemagento
magentocommunity-edition>= 2.4.4-p1 < 2.4.4-p102.4.4-p10
magentocommunity-edition>= 2.4.5-p1 < 2.4.5-p92.4.5-p9
magentocommunity-edition>= 2.4.6-p1 < 2.4.6-p72.4.6-p7
magentocommunity-edition>= 2.4.7-beta1 < 2.4.7-p22.4.7-p2
magentoproject-community-edition0 – 2.0.2