First published: Tue Apr 08 2025(Updated: )
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to gain unauthorized access to protected resources by obtaining sensitive credential information. Exploitation of this issue does not require user interaction.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Magento Commerce | <2.4.8-beta2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27192 is classified as a high severity vulnerability due to its potential to allow security feature bypass by privileged attackers.
To fix CVE-2025-27192, it is recommended to upgrade to Adobe Commerce versions later than 2.4.8-beta2.
CVE-2025-27192 affects Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, and 2.4.8-beta2 and earlier.
CVE-2025-27192 can be exploited by high privileged attackers to gain unauthorized access through security feature bypass.
The disclosure date for CVE-2025-27192 is not mentioned in the provided information.