CVE-2024-39402: Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an admin attacker. Exploitation of this issue requires user interaction and scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39402?
CVE-2024-39402 has a critical severity rating due to its potential for arbitrary code execution by an attacker with admin access.
How do I fix CVE-2024-39402?
To fix CVE-2024-39402, update Adobe Commerce to versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10, or later.
Which versions are vulnerable to CVE-2024-39402?
CVE-2024-39402 affects Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9, and earlier.
What type of vulnerability is CVE-2024-39402?
CVE-2024-39402 is classified as an OS Command Injection vulnerability.
Who is affected by CVE-2024-39402?
Administrators using Adobe Commerce versions listed in the CVE are at risk if they do not apply the necessary updates.