CVE-2023-22250: Adobe Commerce Improper Access Control Security feature bypass
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-22250.
Which versions of Adobe Commerce are affected by this vulnerability?
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected.
What is the severity of CVE-2023-22250?
The severity of CVE-2023-22250 is medium with a CVSS score of 5.3.
What is the impact of the vulnerability?
The vulnerability could result in a security feature bypass and impact the availability of a user's minor feature.
Where can I find more information about CVE-2023-22250?
You can find more information about CVE-2023-22250 on the Adobe security advisory page: https://helpx.adobe.com/security/products/magento/apsb23-17.html