CVE-2024-39413: An unauthorized user can export the Invoiced Sales Report
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39413?
CVE-2024-39413 has been classified with a low severity due to an improper authorization vulnerability.
How do I fix CVE-2024-39413?
To fix CVE-2024-39413, users should upgrade Adobe Commerce to the latest supported version.
Which versions are affected by CVE-2024-39413?
CVE-2024-39413 affects Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier.
Who can exploit CVE-2024-39413?
A low-privileged attacker can exploit CVE-2024-39413 to bypass security features and disclose minor data.
What type of vulnerability is CVE-2024-39413?
CVE-2024-39413 is categorized as an Improper Authorization vulnerability.