7.2
CVSSv3

CVE-2022-34253

Published: 16/08/2022 Updated: 07/11/2023
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

Adobe Commerce versions 2.4.3-p2 (and previous versions), 2.3.7-p3 (and previous versions) and 2.4.4 (and previous versions) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution. Exploitation of this issue does not require user interaction.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe commerce 2.3.7

adobe commerce 2.4.3

magento magento 2.4.3

magento magento 2.3.7

magento magento 2.4.4

magento magento

adobe commerce 2.4.4

adobe commerce