CVE-2025-49555: Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in privilege escalation. A high-privileged attacker could trick a victim into executing unintended actions on a web application where the victim is authenticated, potentially allowing unauthorized access or modification of sensitive data. Exploitation of this issue requires user interaction in that a victim must visit a malicious website or click on a crafted link. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49555?
CVE-2025-49555 has been classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-49555?
To mitigate CVE-2025-49555, ensure Adobe Commerce is updated to version 2.4.9-alpha2 or later.
What types of attacks can exploit CVE-2025-49555?
CVE-2025-49555 can be exploited through Cross-Site Request Forgery (CSRF) attacks, allowing unauthorized actions by privileged attackers.
Which versions of Adobe Commerce are affected by CVE-2025-49555?
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14, and earlier are affected by CVE-2025-49555.
What impact does CVE-2025-49555 have on systems?
CVE-2025-49555 allows a high-privileged attacker to execute unintended actions on behalf of a victim user, potentially leading to privilege escalation.