CVE-2024-34109: Adobe Commerce | Improper Input Validation (CWE-20)
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but admin privileges are required.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34109?
CVE-2024-34109 is classified as a critical vulnerability with potential for arbitrary code execution.
How do I fix CVE-2024-34109?
To fix CVE-2024-34109, update affected Adobe Commerce versions to the latest patched version.
Which versions are affected by CVE-2024-34109?
CVE-2024-34109 affects Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8, and earlier.
Does CVE-2024-34109 require user interaction for exploitation?
No, exploitation of CVE-2024-34109 does not require user interaction.
What is the impact of exploiting CVE-2024-34109?
Exploitation of CVE-2024-34109 can lead to arbitrary code execution in the context of the current user.