← Back

CVE-2025-49555

nvd nist
Published: Aug 12, 2025Modified: Aug 15, 2025

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
Exploitability: 1.7 / Impact: 5.8
Source: psirt@adobe.com (Secondary)

Description

Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in privilege escalation. A high-privileged attacker could trick a victim into executing unintended actions on a web application where the victim is authenticated, potentially allowing unauthorized access or modification of sensitive data. Exploitation of this issue requires user interaction in that a victim must visit a malicious website or click on a crafted link. Scope is changed.

Affected (148)

3 products
Commerce
Commerce B2b
Magento
Configuration A
54 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Before 2.4.4
Version 2.4.4
Version 2.4.4 p10
Version 2.4.4 p11
Version 2.4.4 p12
Version 2.4.4 p13
Version 2.4.4 p14
Version 2.4.4 p1
Version 2.4.4 p2
Version 2.4.4 p3
Version 2.4.4 p4
Version 2.4.4 p5
Version 2.4.4 p6
Version 2.4.4 p7
Version 2.4.4 p8
Version 2.4.4 p9
Version 2.4.5
Version 2.4.5 p10
Version 2.4.5 p11
Version 2.4.5 p12
Version 2.4.5 p13
Version 2.4.5 p1
Version 2.4.5 p2
Version 2.4.5 p3
Version 2.4.5 p4
Version 2.4.5 p5
Version 2.4.5 p6
Version 2.4.5 p7
Version 2.4.5 p8
Version 2.4.5 p9
Version 2.4.6
Version 2.4.6 p10
Version 2.4.6 p11
Version 2.4.6 p1
Version 2.4.6 p2
Version 2.4.6 p3
Version 2.4.6 p4
Version 2.4.6 p5
Version 2.4.6 p6
Version 2.4.6 p7
Version 2.4.6 p8
Version 2.4.6 p9
Version 2.4.7
Version 2.4.7 b1
Version 2.4.7 b2
Version 2.4.7 beta3
Version 2.4.7 p1
Version 2.4.7 p2
Version 2.4.7 p3
Version 2.4.7 p4
Version 2.4.7 p5
Version 2.4.7 p6
Version 2.4.8
Version 2.4.8 beta1
Configuration B
52 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Before 1.3.3
Version 1.3.3
Version 1.3.3 p10
Version 1.3.3 p11
Version 1.3.3 p12
Version 1.3.3 p13
Version 1.3.3 p14
Version 1.3.3 p1
Version 1.3.3 p2
Version 1.3.3 p3
Version 1.3.3 p4
Version 1.3.3 p5
Version 1.3.3 p6
Version 1.3.3 p7
Version 1.3.3 p8
Version 1.3.3 p9
Version 1.3.4
Version 1.3.4 p10
Version 1.3.4 p11
Version 1.3.4 p12
Version 1.3.4 p13
Version 1.3.4 p1
Version 1.3.4 p2
Version 1.3.4 p3
Version 1.3.4 p4
Version 1.3.4 p5
Version 1.3.4 p6
Version 1.3.4 p7
Version 1.3.4 p8
Version 1.3.4 p9
Version 1.3.5
Version 1.3.5 p10
Version 1.3.5 p11
Version 1.3.5 p1
Version 1.3.5 p2
Version 1.3.5 p3
Version 1.3.5 p4
Version 1.3.5 p5
Version 1.3.5 p6
Version 1.3.5 p7
Version 1.3.5 p8
Version 1.3.5 p9
Version 1.4.2
Version 1.4.2 p1
Version 1.4.2 p2
Version 1.4.2 p3
Version 1.4.2 p4
Version 1.4.2 p5
Version 1.4.2 p6
Version 1.5.2
Version 1.5.2 p1
Version 1.5.3 alpha1
Configuration C
42 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Before 2.4.5
Version 2.4.5
Version 2.4.5 p10
Version 2.4.5 p11
Version 2.4.5 p12
Version 2.4.5 p13
Version 2.4.5 p1
Version 2.4.5 p2
Version 2.4.5 p3
Version 2.4.5 p4
Version 2.4.5 p5
Version 2.4.5 p6
Version 2.4.5 p7
Version 2.4.5 p8
Version 2.4.5 p9
Version 2.4.6
Version 2.4.6 p10
Version 2.4.6 p11
Version 2.4.6 p1
Version 2.4.6 p2
Version 2.4.6 p3
Version 2.4.6 p4
Version 2.4.6 p5
Version 2.4.6 p6
Version 2.4.6 p7
Version 2.4.6 p8
Version 2.4.6 p9
Version 2.4.7
Version 2.4.7 b1
Version 2.4.7 b2
Version 2.4.7 beta3
Version 2.4.7 p1
Version 2.4.7 p2
Version 2.4.7 p3
Version 2.4.7 p4
Version 2.4.7 p5
Version 2.4.7 p6
Version 2.4.8
Version 2.4.8 beta1
Version 2.4.8 beta2
Version 2.4.8 p1
Version 2.4.9 alpha1

References (1)

Timeline

No history available yet.