CVE-2023-38249: Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead in arbitrary code execution by an admin-privilege authenticated attacker. Exploitation of this issue does not require user interaction and attack complexity is high as it requires knowledge of tooling beyond just using the UI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38249?
CVE-2023-38249 has been reported as a critical severity vulnerability that allows for SQL injection, leading potentially to arbitrary code execution.
How do I fix CVE-2023-38249?
To fix CVE-2023-38249, upgrade Adobe Commerce to the latest version or apply the security patches provided by Adobe.
Which Adobe Commerce versions are affected by CVE-2023-38249?
CVE-2023-38249 affects Adobe Commerce versions 2.4.7-beta1 and earlier, 2.4.6-p2 and earlier, 2.4.5-p4 and earlier, and 2.4.4-p5 and earlier.
What type of vulnerability is CVE-2023-38249?
CVE-2023-38249 is an SQL injection vulnerability due to improper neutralization of special elements in an SQL command.
Can CVE-2023-38249 be exploited remotely?
Yes, CVE-2023-38249 can be exploited remotely, allowing attackers to execute arbitrary SQL commands within the affected systems.