PT-2025-15647 · Adobe · Commerce

Published

2025-04-08

·

Updated

2025-04-30

·

CVE-2025-27189

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Adobe Commerce versions 2.4.7-p4 through 2.4.8-beta2 and earlier
Description: The issue is a Cross-Site Request Forgery (CSRF) vulnerability that could be exploited to cause a denial-of-service condition. An attacker could trick a logged-in user into submitting a forged request to the vulnerable application, which may disrupt service availability. Exploitation of this issue requires user interaction, typically in the form of clicking a malicious link or visiting an attacker-controlled website.
Recommendations: For Adobe Commerce versions 2.4.7-p4 and earlier, update to a version later than 2.4.8-beta2 to resolve the issue. For Adobe Commerce version 2.4.8-beta2 and earlier, update to a version later than 2.4.8-beta2 to resolve the issue. As a temporary workaround, consider restricting access to the application to minimize the risk of exploitation.

Fix

DoS

CSRF

Weakness Enumeration

Related Identifiers

BDU:2025-04783
CVE-2025-27189

Affected Products

Commerce