cbcvebase.
CVE-2025-49555
published 2025-08-12

CVE-2025-49555: Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Cross-Site Request Forgery (CSRF)…

high8.1CVSS 3.1
AVNACLPRHUIRSCCHIHAN
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in privilege escalation. A high-privileged attacker could trick a victim into executing unintended actions on a web application where the victim is authenticated, potentially allowing unauthorized access or modification of sensitive data. Exploitation of this issue requires user interaction in that a victim must visit a malicious website or click on a crafted link. Scope is changed.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
adobeadobe_commerce<= 2.4.4-p14
adobecommerce< 2.4.42.4.4
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobecommerce_b2b< 1.3.31.3.3
adobecommerce_b2b
adobecommerce_b2b
adobecommerce_b2b
adobecommerce_b2b
adobecommerce_b2b
adobecommerce_b2b
adobemagento< 2.4.52.4.5
adobemagento
adobemagento
adobemagento
adobemagento
adobemagento
magentocommunity-edition>= 0 < 2.4.5-p142.4.5-p14
magentocommunity-edition>= 2.4.6-p1 < 2.4.6-p122.4.6-p12
magentocommunity-edition>= 2.4.7-beta1 < 2.4.7-p72.4.7-p7
magentocommunity-edition>= 2.4.8-beta1 < 2.4.8-p22.4.8-p2
magentocommunity-edition>= 2.4.9-alpha1 < 2.4.9-alpha22.4.9-alpha2