CVE-2024-39400: DOM XSS through integrations can impact other admins
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an admin attacker to inject and execute arbitrary JavaScript code within the context of the user's browser session. Exploitation of this issue requires user interaction, such as convincing a victim to click on a malicious link. Confidentiality and integrity impact is high as it affects other admin accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39400?
CVE-2024-39400 has been classified as a critical vulnerability due to its potential for arbitrary JavaScript code execution.
How do I fix CVE-2024-39400?
To remediate CVE-2024-39400, you should update Adobe Commerce to the latest version provided by Adobe that resolves this vulnerability.
Which Adobe Commerce versions are affected by CVE-2024-39400?
CVE-2024-39400 affects Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9, and earlier versions.
Can CVE-2024-39400 be exploited by non-admin users?
No, CVE-2024-39400 can be exploited only by admin attackers due to the nature of the vulnerability.
What type of vulnerability is CVE-2024-39400?
CVE-2024-39400 is a DOM-based Cross-Site Scripting (XSS) vulnerability.