NA

CVE-2023-38219

Published: 13/10/2023 Updated: 14/10/2023
CVSS v3 Base Score: 8.7 | Impact Score: 5.8 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Adobe Commerce versions 2.4.7-beta1 (and previous versions), 2.4.6-p2 (and previous versions), 2.4.5-p4 (and previous versions) and 2.4.4-p5 (and previous versions) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged malicious user to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Payload is stored in an admin area, resulting in high confidentiality and integrity impact.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe commerce 2.3.7

adobe commerce 2.4.3

adobe commerce 2.4.4

adobe commerce 2.4.5

adobe commerce 2.4.6

adobe magento 2.4.4

adobe magento 2.4.5

adobe magento 2.4.6

adobe commerce 2.4.0

adobe commerce 2.4.1

adobe commerce 2.4.2

adobe magento 2.4.7

adobe commerce 2.4.7