← Back

CVE-2025-24426

nvd nist
Published: Feb 11, 2025Modified: Apr 16, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.

Affected (15)

Products: Adobe: Commerce B2b
1 product
Commerce B2b
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Before 1.3.3
Version 1.3.3
Version 1.3.3 p10
Version 1.3.3 p11
Version 1.3.4
Version 1.3.4 p10
Version 1.3.4 p9
Version 1.3.5
Version 1.3.5 p7
Version 1.3.5 p8
Version 1.4.2
Version 1.4.2 p1
Version 1.4.2 p2
Version 1.4.2 p3
Version 1.5.0

References (1)

Timeline

No history available yet.