CVE-2022-24086

CRITICAL9.8⚠ KEVEPSS 93.7%

Magento improper input validation vulnerability

發布日:2022/2/17修改日:2025/10/22加入 CISA KEV 日:2022/2/15
也稱為:GHSA-f8fv-f786-9933BIT-magento-2022-24086

描述

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H

參考連結(4)