CVE-2022-34257: Adobe Commerce Stored XSS Arbitrary code execution
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34257?
The severity of CVE-2022-34257 is medium with a CVSS score of 6.1.
What is the vulnerability description of CVE-2022-34257?
CVE-2022-34257 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier), and 2.4.4 (and earlier), which allows an attacker to inject malicious scripts into vulnerable form fields.
Which software versions are affected by CVE-2022-34257?
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier), and 2.4.4 (and earlier) are affected by CVE-2022-34257.
How can an attacker exploit CVE-2022-34257?
An attacker can exploit CVE-2022-34257 by injecting malicious JavaScript into vulnerable form fields, which may be executed in a victim's browser.
Is there a fix available for CVE-2022-34257?
Yes, Adobe has released security updates to fix the CVE-2022-34257 vulnerability. It is recommended to update to the latest version of Adobe Commerce.