PT-2022-1535 · Adobe · Commerce
Published
2022-02-13
·
Updated
2025-07-30
·
CVE-2022-24086
10
Critical
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions:**
Adobe Commerce versions 2.4.3-p1 and earlier
Adobe Commerce versions 2.3.7-p2 and earlier
Magento Open Source versions 2.4.3-p1 and earlier
Magento Open Source versions 2.3.7-p2 and earlier
**Description:**
This vulnerability involves an improper input validation issue during the checkout process. Exploitation does not require user interaction and could result in arbitrary code execution. Reports indicate an ongoing server-side template injection campaign, dubbed “Xurum”, actively exploiting this flaw. The campaign has been observed since at least January 2023, and has compromised over 500 sites. Attack vectors include creating malicious client accounts with crafted code in name/surname fields, injecting backdoors via VAT fields in orders, and replacing core files with malicious versions. Successful exploitation allows attackers to gain full database access and execute PHP processes.
**Recommendations:**
Adobe Commerce versions prior to 2.4.3-p1
Adobe Commerce versions prior to 2.3.7-p2
Magento Open Source versions prior to 2.4.3-p1
Magento Open Source versions prior to 2.3.7-p2
Exploit
Fix
RCE
Weakness Enumeration
Related Identifiers
Affected Products
References · 65
- 🔥 https://github.com/Mr-xn/CVE-2022-24086⭐ 36 🔗 7 · Exploit
- 🔥 https://github.com/oK0mo/CVE-2022-24086-RCE-PoC⭐ 5 🔗 3 · Exploit
- 🔥 https://github.com/pescepilota/CVE-2022-24086⭐ 5 🔗 1 · Exploit
- 🔥 https://github.com/akr3ch/CVE-2022-24086⭐ 2 🔗 1 · Exploit
- 🔥❌ https://github.com/shakeman8/CVE-2022-24086-RCE · Exploit, Deleted
- https://safe-surf.ru/specialists/bulletins-nkcki/675634 · Security Note
- https://osv.dev/vulnerability/GHSA-f8fv-f786-9933 · Vendor Advisory
- https://osv.dev/vulnerability/BIT-magento-2022-24086 · Vendor Advisory
- https://osv.dev/vulnerability/CVE-2022-24086 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-24086 · Security Note
- https://helpx.adobe.com/security/products/magento/apsb22-12.html · Vendor Advisory
- https://bdu.fstec.ru/vul/2022-00739 · Security Note
- https://github.com/magento/magento2⭐ 11831 🔗 9389 · Note
- https://twitter.com/Swati_THN/status/1691076367394185216 · Twitter Post
- https://t.me/true_secator/3461 · Telegram Post