CVE-2024-39403: Stored XSS through Webhook module public key configuration
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Confidentiality impact is high due to the attacker being able to exfiltrate sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39403?
CVE-2024-39403 is considered a moderate severity vulnerability due to its potential for exploitation by low-privileged attackers.
How do I fix CVE-2024-39403?
To fix CVE-2024-39403, upgrade Adobe Commerce to a version that includes the patch for this vulnerability.
What versions of Adobe Commerce are affected by CVE-2024-39403?
CVE-2024-39403 affects Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9, and earlier versions.
Can CVE-2024-39403 be exploited remotely?
Yes, CVE-2024-39403 can potentially be exploited remotely as it allows attackers to inject malicious scripts into vulnerable form fields.
Who is at risk due to CVE-2024-39403?
Users and administrators of affected Adobe Commerce versions are at risk of XSS attacks due to CVE-2024-39403.