CVE-2022-34253

EUVD-2022-6539
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution. Exploitation of this issue does not require user interaction.
aka Blind XPath Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
adobeCNA
9.1 CRITICAL
NETWORK
LOW
HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
adobecommerce
2.3.0 ≤
𝑥
< 2.3.7
adobecommerce
2.4.0 ≤
𝑥
< 2.4.3
adobecommerce
2.3.7
adobecommerce
2.3.7:p1
adobecommerce
2.3.7:p2
adobecommerce
2.3.7:p3
adobecommerce
2.4.3
adobecommerce
2.4.3:p1
adobecommerce
2.4.3:p2
adobecommerce
2.4.4
magentomagento
2.3.0 ≤
𝑥
< 2.3.7
magentomagento
2.4.0 ≤
𝑥
< 2.4.3
magentomagento
2.3.7
magentomagento
2.3.7:p1
magentomagento
2.3.7:p2
magentomagento
2.3.7:p3
magentomagento
2.4.3
magentomagento
2.4.3:p1
magentomagento
2.4.3:p2
magentomagento
2.4.4
𝑥
= Vulnerable software versions