CVE-2023-22249: Adobe Commerce Stored XSS Arbitrary code execution
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Adobe Commerce vulnerability?
The vulnerability ID for this Adobe Commerce vulnerability is CVE-2023-22249.
What is the severity of CVE-2023-22249?
The severity of CVE-2023-22249 is medium.
What is the affected software?
The affected software includes Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier).
What can a high-privileged attacker do with this vulnerability?
A high-privileged attacker can use this vulnerability to inject malicious scripts into vulnerable form fields.
How can I fix CVE-2023-22249?
To fix CVE-2023-22249, update to Adobe Commerce versions 2.4.4-p3 and 2.4.5-p2 (or later).