9.1
CVSSv3

CVE-2024-20719

Published: 15/02/2024 Updated: 16/02/2024
CVSS v3 Base Score: 9.1 | Impact Score: 6 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and previous versions are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin malicious user to inject malicious scripts into every admin page. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field, that could be leveraged to gain admin access.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe commerce 2.4.4

adobe commerce 2.4.5

adobe commerce 2.4.6