PT-2022-4385 · Adobe · Commerce
Published
2022-08-09
·
Updated
2024-03-06
·
CVE-2022-34257
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Commerce versions 2.4.3-p2 and earlier
Adobe Commerce versions 2.3.7-p3 and earlier
Adobe Commerce versions 2.4.4 and earlier
Description
The issue is related to a stored Cross-Site Scripting (XSS) vulnerability that could allow an attacker to inject malicious scripts into vulnerable form fields. This could lead to the execution of malicious JavaScript in a victim's browser when they browse to the page containing the vulnerable field. The vulnerability is also described as being related to the lack of protection of the web page structure, which could allow a remote attacker to conduct cross-site scripting attacks.
Recommendations
For Adobe Commerce versions 2.4.3-p2 and earlier, update to a version that includes the fix for this issue.
For Adobe Commerce versions 2.3.7-p3 and earlier, update to a version that includes the fix for this issue.
For Adobe Commerce versions 2.4.4 and earlier, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to vulnerable form fields until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Commerce