CVE-2023-29293: Adobe Commerce | Improper Input Validation (CWE-20)
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An admin privileged attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-29293.
Which versions of Adobe Commerce are affected by this vulnerability?
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier), and 2.4.4-p3 (and earlier) are affected by this vulnerability.
How severe is CVE-2023-29293?
CVE-2023-29293 has a severity level of 2.7, which is considered low.
What is the impact of this vulnerability?
This vulnerability could result in a security feature bypass and impact the availability of a user.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following link: [Adobe Security Bulletin APSB23-35](https://helpx.adobe.com/security/products/magento/apsb23-35.html).