PT-2022-4385 · Adobe · Commerce

Published

2022-08-09

·

Updated

2024-03-06

·

CVE-2022-34257

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Adobe Commerce versions 2.4.3-p2 and earlier Adobe Commerce versions 2.3.7-p3 and earlier Adobe Commerce versions 2.4.4 and earlier
Description The issue is related to a stored Cross-Site Scripting (XSS) vulnerability that could allow an attacker to inject malicious scripts into vulnerable form fields. This could lead to the execution of malicious JavaScript in a victim's browser when they browse to the page containing the vulnerable field. The vulnerability is also described as being related to the lack of protection of the web page structure, which could allow a remote attacker to conduct cross-site scripting attacks.
Recommendations For Adobe Commerce versions 2.4.3-p2 and earlier, update to a version that includes the fix for this issue. For Adobe Commerce versions 2.3.7-p3 and earlier, update to a version that includes the fix for this issue. For Adobe Commerce versions 2.4.4 and earlier, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to vulnerable form fields until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-05248
BIT-MAGENTO-2022-34257
CVE-2022-34257
GHSA-RG7P-WMGJ-F374

Affected Products

Commerce