PT-2022-4896 · Adobe · Commerce

Published

2022-08-09

·

Updated

2024-03-06

·

CVE-2022-34253

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Commerce versions 2.4.3-p2 and earlier Adobe Commerce versions 2.3.7-p3 and earlier Adobe Commerce versions 2.4.4 and earlier
Description The issue is related to errors in processing XML requests, which can allow a remote attacker to execute arbitrary code using specially crafted XML data. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution. Exploitation of this issue does not require user interaction.
Recommendations For Adobe Commerce versions 2.4.3-p2 and earlier, update to a version that fixes the XML Injection vulnerability in the Widgets Module. For Adobe Commerce versions 2.3.7-p3 and earlier, update to a version that fixes the XML Injection vulnerability in the Widgets Module. For Adobe Commerce versions 2.4.4 and earlier, update to a version that fixes the XML Injection vulnerability in the Widgets Module. As a temporary workaround, consider restricting access to the Widgets Module to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-06057
BIT-MAGENTO-2022-34253
CVE-2022-34253
GHSA-CJ7W-PM77-HVG6

Affected Products

Commerce