CVE-2023-38221: Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead in arbitrary code execution by an admin-privilege authenticated attacker. Exploitation of this issue does not require user interaction and attack complexity is high as it requires knowledge of tooling beyond just using the UI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38221?
CVE-2023-38221 has been classified with a high severity level due to its potential to allow SQL injection leading to arbitrary code execution.
How do I fix CVE-2023-38221?
To fix CVE-2023-38221, you should update your Adobe Commerce or Magento Open Source installation to the latest patched version.
Which Adobe Commerce versions are affected by CVE-2023-38221?
Adobe Commerce versions 2.4.7-beta1 and earlier, along with 2.4.6-p2 and earlier, are affected by CVE-2023-38221.
Does CVE-2023-38221 affect Adobe Magento Open Source?
Yes, CVE-2023-38221 also affects Adobe Magento Open Source versions similar to those of Adobe Commerce.
What type of vulnerability is CVE-2023-38221?
CVE-2023-38221 is an SQL Injection vulnerability caused by improper neutralization of special elements used in SQL commands.