CVE-2024-20758: Adobe Commerce | Improper Input Validation (CWE-20)
Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but the attack complexity is high.
Other sources
Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution on the underlying filesystem. Exploitation of this issue does not require user interaction, but the attack complexity is high.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20758?
CVE-2024-20758 has a critical severity rating due to the potential for arbitrary code execution.
How do I fix CVE-2024-20758?
To fix CVE-2024-20758, update your Adobe Commerce installation to version 2.4.7 or later.
What versions of Adobe Commerce are affected by CVE-2024-20758?
CVE-2024-20758 affects Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, and 2.4.7-beta3 and earlier.
Is user interaction required to exploit CVE-2024-20758?
Exploitation of CVE-2024-20758 does not require user interaction, making it more critical.
What are the potential consequences of exploiting CVE-2024-20758?
Exploiting CVE-2024-20758 could lead to arbitrary code execution in the context of the current user, compromising system security.