7.5
CVSSv3

CVE-2023-38207

Published: 09/08/2023 Updated: 14/09/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Adobe Commerce versions 2.4.6-p1 (and previous versions), 2.4.5-p3 (and previous versions) and 2.4.4-p4 (and previous versions) are affected by a XML Injection (aka Blind XPath Injection) vulnerability that could lead in minor arbitrary file system read. Exploitation of this issue does not require user interaction.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe commerce 2.4.4

adobe commerce 2.4.5

adobe commerce

adobe commerce 2.4.6