PT-2022-4897 · Adobe · Commerce

Published

2022-08-09

·

Updated

2024-03-06

·

CVE-2022-34254

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Commerce versions 2.4.3-p2 and earlier Adobe Commerce versions 2.3.7-p3 and earlier Adobe Commerce versions 2.4.4 and earlier
Description The issue is related to an Improper Limitation of a Pathname to a Restricted Directory, also known as a Path Traversal vulnerability. This could allow an attacker to inject malicious scripts into the vulnerable endpoint. A low-privileged attacker could exploit this to read local files and perform Stored XSS. Exploitation does not require user interaction. The vulnerability can be exploited by a remote attacker to execute arbitrary code in the context of the current user.
Recommendations For versions 2.4.3-p2 and earlier, update to a version that includes the fix for this issue. For versions 2.3.7-p3 and earlier, update to a version that includes the fix for this issue. For versions 2.4.4 and earlier, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to sensitive endpoints to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2022-06058
BIT-MAGENTO-2022-34254
CVE-2022-34254
GHSA-FX9G-G9Q6-X3JX

Affected Products

Commerce