CVE-2022-35698: Adobe Commerce Stored XSS Arbitrary code execution
Adobe Commerce versions 2.4.3-p3 (and earlier), 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
Other sources
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Adobe Commerce issue?
The vulnerability ID for this Adobe Commerce issue is CVE-2022-35698.
Which versions of Adobe Commerce are affected by this vulnerability?
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected.
What is the severity level of CVE-2022-35698?
CVE-2022-35698 has a severity level of 5.4 (Critical).
Is user interaction required to exploit this vulnerability?
No, exploitation of this vulnerability does not require user interaction.
What is the impact of CVE-2022-35698?
Exploiting this vulnerability could result in post-authentication arbitrary code execution.