CVE-2023-38250: Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead in arbitrary code execution by an admin-privilege authenticated attacker. Exploitation of this issue does not require user interaction and attack complexity is high as it requires knowledge of tooling beyond just using the UI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38250?
CVE-2023-38250 is classified as a critical severity vulnerability due to its potential for arbitrary code execution through SQL injection.
How do I fix CVE-2023-38250?
To fix CVE-2023-38250, upgrade to the latest patched version of Adobe Commerce or Magento Open Source as specified in Adobe's security advisory.
What versions are affected by CVE-2023-38250?
CVE-2023-38250 affects Adobe Commerce versions 2.4.7-beta1 and earlier, along with versions 2.4.6-p2, 2.4.5-p4, and 2.4.4-p5 among others.
What can happen if CVE-2023-38250 is exploited?
If CVE-2023-38250 is exploited, it could allow attackers to execute arbitrary code on the affected system.
Is there a workaround for CVE-2023-38250?
There are no known workarounds for CVE-2023-38250; the recommended action is to apply the latest updates.