CVE-2022-24086
16.02.2022, 17:15
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.Enginsight
| Vendor | Product | Version |
|---|---|---|
| adobe | commerce | 𝑥 < 2.3.0 |
| adobe | commerce | 2.3.3 ≤ 𝑥 ≤ 2.3.6 |
| adobe | commerce | 2.4.0 ≤ 𝑥 ≤ 2.4.2 |
| adobe | commerce | 2.3.7:p1 |
| adobe | commerce | 2.3.7:p2 |
| adobe | commerce | 2.4.3 |
| adobe | commerce | 2.4.3:p1 |
| adobe | magento | 𝑥 < 2.3.0 |
| adobe | magento | 2.3.3 < 𝑥 ≤ 2.3.6 |
| adobe | magento | 2.4.0 ≤ 𝑥 ≤ 2.4.2 |
| adobe | magento | 2.3.7:p1 |
| adobe | magento | 2.3.7:p2 |
| adobe | magento | 2.4.3 |
| adobe | magento | 2.4.3:p1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration