CVE-2023-29295: Insecure Direct Object Reference (IDOR) in Create Quote Function
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass a minor functionality. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is Adobe Commerce versions 2.4.6 (and earlier) 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) vulnerability (CVE-2023-29295)?
Adobe Commerce versions 2.4.6 (and earlier) 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass.
How does the CVE-2023-29295 vulnerability impact Adobe Commerce?
The CVE-2023-29295 vulnerability in Adobe Commerce allows a low-privileged attacker to bypass a minor functionality.
What is the severity of the Adobe Commerce versions 2.4.6 (and earlier) 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) vulnerability?
The severity of the CVE-2023-29295 vulnerability in Adobe Commerce is medium with a severity value of 4.3.
How can I fix the Adobe Commerce versions 2.4.6 (and earlier) 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) vulnerability?
To fix the CVE-2023-29295 vulnerability in Adobe Commerce, it is recommended to update to a patched version provided by Adobe.
Where can I find more information about the Adobe Commerce versions 2.4.6 (and earlier) 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) vulnerability?
More information about the CVE-2023-29295 vulnerability in Adobe Commerce can be found at Adobe's Security Advisory (APSB23-35) at the provided reference link.