PT-2022-6430 · Adobe · Commerce

Published

2022-10-11

·

Updated

2022-10-19

·

CVE-2022-35698

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Commerce versions 2.4.4-p1 and earlier Adobe Commerce versions 2.4.5 and earlier
Description The issue is related to a Stored Cross-site Scripting problem. It does not require user interaction to be exploited and could lead to post-authentication arbitrary code execution. The vulnerability exists due to inadequate protection of the web page structure, which could allow a remote attacker to execute arbitrary code.
Recommendations For Adobe Commerce versions 2.4.4-p1 and earlier, update to a version that addresses this issue. For Adobe Commerce versions 2.4.5 and earlier, update to a version that addresses this issue. As a temporary workaround, consider restricting access to sensitive areas of the platform to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01235
CVE-2022-35698
GHSA-4VJ2-426R-JM3G

Affected Products

Commerce