CVE-2023-29289: Adobe Commerce XML Injection Security feature bypass
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an XML Injection vulnerability. An attacker with low privileges can trigger a specially crafted script to a security feature bypass. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Adobe Commerce vulnerability?
The vulnerability ID for this Adobe Commerce vulnerability is CVE-2023-29289.
What is the severity level of CVE-2023-29289?
The severity level of CVE-2023-29289 is medium (6.5).
Which versions of Adobe Commerce are affected by CVE-2023-29289?
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier), and 2.4.4-p3 (and earlier) are affected by CVE-2023-29289.
How can the XML Injection vulnerability be exploited?
The XML Injection vulnerability can be exploited by an attacker with low privileges triggering a specially crafted script to bypass security features.
Where can I find more information about CVE-2023-29289?
More information about CVE-2023-29289 can be found at the following link: https://helpx.adobe.com/security/products/magento/apsb23-35.html