PT-2025-6368 · Adobe · Commerce

Published

2025-02-11

·

Updated

2025-02-16

·

CVE-2025-24434

CVSS v2.0

9.7

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier
Description The issue is related to an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. This vulnerability enables unauthorized access without user interaction and could lead to possible account takeovers.
Recommendations For Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier, update to a version that includes the security patch APSB25-08 to fix the vulnerability. At the moment, there is no information about other specific newer versions that contain a fix for this vulnerability.

Fix

LPE

Improper Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-05397
CVE-2025-24434
GHSA-FPPQ-F2M6-XV5C

Affected Products

Commerce