CVE-2023-22251: Adobe Commerce Incorrect Authorization Security feature bypass
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorrect Authorization vulnerability. A low-privileged authenticated attacker could leverage this vulnerability to achieve minor information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Adobe Commerce vulnerability?
The vulnerability ID of this Adobe Commerce vulnerability is CVE-2023-22251.
Which versions of Adobe Commerce are affected by this vulnerability?
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by this vulnerability.
What is the severity level of this vulnerability?
The severity level of this vulnerability is medium with a CVSS score of 4.3.
What is the impact of this vulnerability?
The impact of this vulnerability is minor information disclosure.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following link: [Adobe Security Bulletin APSB23-17](https://helpx.adobe.com/security/products/magento/apsb23-17.html).