CVE-2024-45117Improper Input Validation in Adobe Commerce

Severity
7.6HIGHNVD
EPSS
0.3%
top 50.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10

Description

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An admin attacker could exploit this vulnerability to read files from the system outside of the intended directories via PHP filter chain and also can have a low-availability impact on the service. Exploitation of this issue does not require user interaction and scope is changed.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:LExploitability: 2.3 | Impact: 4.7

Affected Packages5 packages

CVEListV5adobe/adobe_commerce2.4.4-p10
NVDadobe/commerce9 versions+8
NVDadobe/commerce_b2b4 versions+3
NVDadobe/magento5 versions+4
Packagistmagento/community-edition2.4.7-beta12.4.7-p3+3

🔴Vulnerability Details

3
GHSA
Magento Open Source Improper Input Validation vulnerability2024-10-10
OSV
Magento Open Source Improper Input Validation vulnerability2024-10-10
CVEList
Adobe Commerce | Improper Input Validation (CWE-20)2024-10-10
CVE-2024-45117 — Improper Input Validation in Adobe | cvebase