CVE-2024-20719: [Adobe Commerce] Stored XSS from low privileged admin user on every admin page, bypassing CVE-2023-29297
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into every admin page. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field, that could be leveraged to gain admin access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.4.4-p7 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.4.5-p6 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.4.6-p4 - Upgrade
Upgrade
Adobe Commerceto a version that resolves this vulnerability.Fixed in 2.4.6-p3 - Upgrade
Upgrade
Adobe Commerceto a version that resolves this vulnerability.Fixed in 2.4.5-p5 - Upgrade
Upgrade
Adobe Commerceto a version that resolves this vulnerability.Fixed in 2.4.4-p6
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20719?
CVE-2024-20719 is classified as a stored Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2024-20719?
To fix CVE-2024-20719, upgrade to Adobe Commerce version 2.4.6-p4 or later.
Which versions are affected by CVE-2024-20719?
CVE-2024-20719 affects Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6, and earlier versions.
What types of attacks can CVE-2024-20719 facilitate?
CVE-2024-20719 can facilitate attacks that allow admin attackers to inject malicious scripts into admin pages.
Is CVE-2024-20719 considered critical?
While the severity can vary based on context, CVE-2024-20719 poses significant risks due to its potential for XSS attacks.