CVE-2024-39401: Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an admin attacker. Exploitation of this issue requires user interaction and scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39401?
CVE-2024-39401 is classified as a critical severity vulnerability due to the potential for arbitrary code execution by an admin attacker.
How do I fix CVE-2024-39401?
To fix CVE-2024-39401, update Adobe Commerce to at least version 2.4.8 or apply the appropriate security patches provided by Adobe.
Which versions are affected by CVE-2024-39401?
CVE-2024-39401 affects Adobe Commerce versions 2.4.7-p1 and earlier, including versions 2.4.6-p6, 2.4.5-p8, and 2.4.4-p9.
What type of vulnerability is CVE-2024-39401?
CVE-2024-39401 is an OS Command Injection vulnerability that allows an attacker to execute arbitrary code.
Who can exploit CVE-2024-39401?
CVE-2024-39401 can be exploited by admin-level attackers who have access to the affected systems.