CVE-2024-39416: Unauthorized user can export Orders Sale Report
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39416?
CVE-2024-39416 is categorized as a low severity vulnerability affecting Adobe Commerce.
How do I fix CVE-2024-39416?
To mitigate CVE-2024-39416, update to Adobe Commerce version 2.4.7-p2 or later.
What types of systems are affected by CVE-2024-39416?
CVE-2024-39416 affects Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, and earlier versions.
Can attackers exploit CVE-2024-39416 remotely?
Yes, a low-privileged attacker could exploit CVE-2024-39416 remotely by bypassing security measures.
What kind of vulnerability is CVE-2024-39416?
CVE-2024-39416 is classified as an Improper Authorization vulnerability leading to a security feature bypass.