CVE-2025-27189: Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could be exploited to cause a denial-of-service condition. An attacker could trick a logged-in user into submitting a forged request to the vulnerable application, which may disrupt service availability. Exploitation of this issue requires user interaction, typically in the form of clicking a malicious link or visiting an attacker-controlled website.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27189?
CVE-2025-27189 is classified as a moderate severity vulnerability due to its potential to cause a denial-of-service condition.
Who is affected by CVE-2025-27189?
CVE-2025-27189 affects Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, and earlier, including 2.4.8-beta2.
How do I fix CVE-2025-27189?
To fix CVE-2025-27189, upgrade to the latest version of Adobe Commerce that is not affected by this vulnerability.
What type of vulnerability is CVE-2025-27189?
CVE-2025-27189 is a Cross-Site Request Forgery (CSRF) vulnerability.
What could an attacker achieve by exploiting CVE-2025-27189?
An attacker could exploit CVE-2025-27189 to trick a logged-in user into submitting a forged request, potentially leading to a denial-of-service condition.