CVE-2024-45116: Adobe Commerce | Cross-site Scripting (XSS) (CWE-79)
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code. If an admin attacker can trick a user into clicking a specially crafted link or submitting a form, malicious scripts may be executed within the context of the victim's browser and have high impact on confidentiality and integrity. Exploitation of this issue requires user interaction.
Other sources
Magento Open Source versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code. If an admin attacker can trick a user into clicking a specially crafted link or submitting a form, malicious scripts may be executed within the context of the victim's browser and have high impact on confidentiality and integrity. Exploitation of this issue requires user interaction.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45116?
CVE-2024-45116 is classified as a critical Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2024-45116?
To fix CVE-2024-45116, upgrade to Adobe Commerce version 2.4.4-p11, 2.4.5-p10, 2.4.6-p8, or 2.4.7-p3.
What versions of Adobe Commerce are affected by CVE-2024-45116?
Adobe Commerce versions 2.4.4, 2.4.5, 2.4.6, and 2.4.7 are affected by CVE-2024-45116.
What can an attacker achieve with CVE-2024-45116?
An attacker can exploit CVE-2024-45116 to execute arbitrary code by tricking a user into interacting with a malicious link or form.
Who is at risk due to CVE-2024-45116?
Users of affected versions of Adobe Commerce are at risk of exploitation from attackers leveraging this XSS vulnerability.