Adobe Commerce security update-CVE-2022-24086
NAME
Adobe – Multiple
- Platforms Affected:
Multiple - Risk Level:
medium - CVE Type:
Improper input validation
DESCRIPTION
CVE-2022-24086 is an improper input validation vulnerability impacting Adobe Commerce versions 2.3.7 p2 and earlier and Adobe Commerce versions 2.4.3 p1 and earlier. A proof of concept (PoC) was not observed publicly or in the underground. Adobe claimed to be aware of the vulnerability being actively exploited in the wild.
CVSS Information:
- CVSS 2.0 SCORE:
- CVSS 3.0 SCORE: 9.8
- Exploit Disclosed in the Public:
true - Exploit Weaponised:
true - PoC Link:
hXXps://helpx[.]adobe[.]com/security/products/magento/apsb22-12[.]html
MITIGATION
Adobe addressed the vulnerability in a security bulletin with updated versions.
- Reference Link:
https://helpx.adobe.com/security/products/magento/apsb22-12.html - Patch Available:
available
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.