First published: Tue Feb 11 2025(Updated: )
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Magento Commerce | <2.4.7 | |
composer/magento/project-community-edition | <=2.0.2 | |
composer/magento/community-edition | <2.4.4-p12 | 2.4.4-p12 |
composer/magento/community-edition | >=2.4.5-p1<2.4.5-p11 | 2.4.5-p11 |
composer/magento/community-edition | >=2.4.6-p1<2.4.6-p9 | 2.4.6-p9 |
composer/magento/community-edition | >=2.4.7-beta1<2.4.7-p4 | 2.4.7-p4 |
composer/magento/community-edition | >=2.4.8-beta1<2.4.8-beta2 | 2.4.8-beta2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24434 is considered a critical vulnerability due to its potential for privilege escalation and unauthorized access.
To fix CVE-2025-24434, update your Adobe Commerce software to versions 2.4.7-beta2 or later.
CVE-2025-24434 affects Adobe Commerce versions up to 2.4.7 and several earlier versions.
CVE-2025-24434 is classified as an Improper Authorization vulnerability.
By exploiting CVE-2025-24434, an attacker could bypass security measures and gain unauthorized access to the system.