CVE-2025-24408: Adobe Commerce | Information Exposure (CWE-200)
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation. A low-privileged attacker could gain unauthorized access to sensitive information. Exploitation of this issue does not require user interaction.
Other sources
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation. A low-privileged attacker could gain unauthorized access to sensitive information. Exploitation of this issue does not require user interaction.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24408?
CVE-2025-24408 is classified as an Information Exposure vulnerability with potential for privilege escalation.
How do I fix CVE-2025-24408?
To fix CVE-2025-24408, upgrade Adobe Commerce to the latest version that is not affected by this vulnerability.
Who is affected by CVE-2025-24408?
CVE-2025-24408 affects Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, and 2.4.4-p11 and earlier.
What could an attacker gain by exploiting CVE-2025-24408?
An attacker exploiting CVE-2025-24408 could gain unauthorized access to sensitive information.
Is CVE-2025-24408 a critical vulnerability?
While CVE-2025-24408 is categorized as low severity, it poses a significant risk due to its potential for privilege escalation.