CVE-2024-39408Cross-Site Request Forgery in Adobe Commerce

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 56.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 14

Description

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changeson behalf of a user. The vulnerability could be exploited by tricking a victim into clicking a link or loading a page that submits a malicious request. Exploitation of this issue requires user interaction.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

NVDadobe/commerce2.4.3+4
CVEListV5adobe/adobe_commerce2.4.4-p9
NVDadobe/magento2.4.3+4
Packagistmagento/community-edition2.4.7-p12.4.7-p2+3

🔴Vulnerability Details

3
GHSA
Magento Open Source Cross-Site Request Forgery vulnerability2024-08-14
CVEList
Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)2024-08-14
OSV
Magento Open Source Cross-Site Request Forgery vulnerability2024-08-14
CVE-2024-39408 — Cross-Site Request Forgery in Adobe | cvebase