CVE-2023-38218: Input Validation
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an improper input validation vulnerability. An authenticated attacker can trigger an insecure direct object reference in the V1/customers/me endpoint to achieve information exposure and privilege escalation.
Other sources
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Incorrect Authorization . An authenticated attacker can exploit this to achieve information exposure and privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38218?
The severity of CVE-2023-38218 is classified as critical.
How do I fix CVE-2023-38218?
To fix CVE-2023-38218, upgrade your Adobe Commerce version to the latest patch available.
Which versions of Adobe Commerce are affected by CVE-2023-38218?
Adobe Commerce versions 2.4.7-beta1 and earlier, 2.4.6-p2 and earlier, 2.4.5-p4 and earlier, and 2.4.4-p5 and earlier are affected.
What is the exploit method for CVE-2023-38218?
CVE-2023-38218 can be exploited through improper input validation leading to insecure direct object references.
Who can exploit CVE-2023-38218?
An authenticated attacker can exploit CVE-2023-38218.