9.1
CVSSv3

CVE-2024-20720

Published: 15/02/2024 Updated: 16/02/2024
CVSS v3 Base Score: 9.1 | Impact Score: 6 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and previous versions are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe commerce 2.4.4

adobe commerce 2.4.5

adobe commerce 2.4.6

Github Repositories

Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) no user interaction is required to exploit this vulnerability.

CVE-2024-20720-PoC Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) no user interaction is required to exploit this vulnerability this script is working with single url and list of urls, and you can chose the name of the shell inside the script, and you can change the content of the shell inside the script too with this do