CVE-2023-38207: Adobe Commerce XML Injection (aka Blind XPath Injection) Arbitrary file system read
Published Aug 9, 2023
·Updated
Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by a XML Injection (aka Blind XPath Injection) vulnerability that could lead in minor arbitrary file system read. Exploitation of this issue does not require user interaction.
Affected Software
19 affected componentsFixes available
Adobe Commerce<2.4.4
Adobe Commerce=2.4.4
Adobe Commerce=2.4.4-p1
Adobe Commerce=2.4.4-p2
Adobe Commerce=2.4.4-p3
Adobe Commerce=2.4.4-p4
Adobe Commerce=2.4.5
Adobe Commerce=2.4.5-p1
Adobe Commerce=2.4.5-p2
Adobe Commerce=2.4.5-p3
Adobe Commerce=2.4.6
Adobe Commerce=2.4.6-p1
composer/magento/project-community-edition<=2.0.2
composer/magento/community-edition>=2.4.4-p1<2.4.4-p5
2.4.4-p5
composer/magento/community-edition>=2.4.5-p1<2.4.5-p4
2.4.5-p4
composer/magento/community-edition=2.4.6-p1
2.4.6-p2
composer/magento/community-edition=2.4.4
composer/magento/community-edition=2.4.5
composer/magento/community-edition=2.4.6
Event History
Aug 9, 2023
CVE Published
via MITRE·07:41 AM
Data Sourced
via MITRE·07:41 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·09:30 AM
Frequently Asked Questions
1
What is the vulnerability ID for this Adobe Commerce vulnerability?
The vulnerability ID for this Adobe Commerce vulnerability is CVE-2023-38207.
2
What is the severity level of CVE-2023-38207?
The severity level of CVE-2023-38207 is high.
3
What is the affected software version for this vulnerability?
The affected software versions for this vulnerability are Adobe Commerce 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier), and 2.4.4-p4 (and earlier).
4
What is the impact of this vulnerability?
This vulnerability could lead to a minor arbitrary file system read.
5
Is user interaction required to exploit this vulnerability?
No, exploitation of this vulnerability does not require user interaction.