← Back

CVE-2022-24086

Published: Feb 16, 2022Modified: Oct 23, 2025CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: psirt@adobe.com (Secondary)

Description

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

Affected (14)

Products: Adobe: Commerce, Magento
2 products
Commerce
Magento
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Before 2.3.0
From 2.3.3 to 2.3.6
From 2.4.0 to 2.4.2
Version 2.3.7 p1
Version 2.3.7 p2
Version 2.4.3
Version 2.4.3 p1
Adobe
Before 2.3.0
After 2.3.3 to 2.3.6
From 2.4.0 to 2.4.2
Version 2.3.7 p1
Version 2.3.7 p2
Version 2.4.3
Version 2.4.3 p1

References (3)

Source: psirt@adobe.com
PatchRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchRelease NotesVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.