CVE-2024-39414: Being able to import/export tax rates without proper privileges
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39414?
CVE-2024-39414 is classified as a low severity vulnerability due to its nature of improper authorization.
How do I fix CVE-2024-39414?
To mitigate CVE-2024-39414, update your Adobe Commerce to the latest patched version.
What versions of Adobe Commerce are affected by CVE-2024-39414?
CVE-2024-39414 affects Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9, and earlier.
Who can exploit CVE-2024-39414?
A low-privileged attacker can exploit CVE-2024-39414 to bypass security features and disclose sensitive information.
What type of vulnerability is CVE-2024-39414?
CVE-2024-39414 is identified as an Improper Authorization vulnerability that allows for security feature bypass.