First published: Fri Oct 14 2022(Updated: )
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Commerce | <2.4.4 | |
Adobe Commerce | =2.4.4 | |
Adobe Commerce | =2.4.4-p1 | |
Adobe Commerce | =2.4.5 | |
Adobe Magento Open Source | <2.4.4 | |
Adobe Magento Open Source | =2.4.4 | |
Adobe Magento Open Source | =2.4.4-p1 | |
Adobe Magento Open Source | =2.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Adobe Commerce issue is CVE-2022-35698.
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected.
CVE-2022-35698 has a severity level of 5.4 (Critical).
No, exploitation of this vulnerability does not require user interaction.
Exploiting this vulnerability could result in post-authentication arbitrary code execution.