PT-2022-6430 · Adobe · Commerce
Published
2022-10-11
·
Updated
2022-10-19
·
CVE-2022-35698
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Adobe Commerce versions 2.4.4-p1 and earlier
Adobe Commerce versions 2.4.5 and earlier
Description
The issue is related to a Stored Cross-site Scripting problem. It does not require user interaction to be exploited and could lead to post-authentication arbitrary code execution. The vulnerability exists due to inadequate protection of the web page structure, which could allow a remote attacker to execute arbitrary code.
Recommendations
For Adobe Commerce versions 2.4.4-p1 and earlier, update to a version that addresses this issue.
For Adobe Commerce versions 2.4.5 and earlier, update to a version that addresses this issue.
As a temporary workaround, consider restricting access to sensitive areas of the platform to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Commerce