4.8
CVSSv3

CVE-2023-22249

Published: 27/03/2023 Updated: 04/04/2023
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 0

Vulnerability Summary

Adobe Commerce versions 2.4.4-p2 (and previous versions) and 2.4.5-p1 (and previous versions) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged malicious user to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe commerce 2.4.4

adobe magento open source

adobe magento open source 2.4.5

adobe magento open source 2.4.4

adobe commerce 2.4.5

adobe commerce