CVE-2022-34255: Adobe Commerce Improper Access Control Privilege escalation
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An attacker with a low privilege account could leverage this vulnerability to perform an account takeover for a victim. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-34255?
CVE-2022-34255 is a vulnerability in Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier), and 2.4.4 (and earlier) that allows privilege escalation.
How severe is CVE-2022-34255?
CVE-2022-34255 has a severity rating of 8.8, which is considered high.
How can CVE-2022-34255 be exploited?
CVE-2022-34255 can be exploited by an attacker with a low privilege account to perform an account takeover.
Which software versions are affected by CVE-2022-34255?
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier), and 2.4.4 (and earlier) are affected by CVE-2022-34255.
Is there a fix for CVE-2022-34255?
Yes, there is a fix available for CVE-2022-34255. It is recommended to update to the latest version of Adobe Commerce to mitigate the vulnerability.