CVE-2023-38219

Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victims browser when they browse to the page containing the vulnerable field. Payload is stored in an admin area, resulting in high confidentiality and integrity impact.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.7 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
adobeCNA
8.7 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
VendorProductVersion
adobecommerce
2.3.7
adobecommerce
2.3.7:p1
adobecommerce
2.3.7:p2
adobecommerce
2.3.7:p3
adobecommerce
2.3.7:p4
adobecommerce
2.3.7:p4-ext1
adobecommerce
2.3.7:p4-ext2
adobecommerce
2.3.7:p4-ext3
adobecommerce
2.3.7:p4-ext4
adobecommerce
2.4.0
adobecommerce
2.4.0:ext-1
adobecommerce
2.4.0:ext-2
adobecommerce
2.4.0:ext-3
adobecommerce
2.4.0:ext-4
adobecommerce
2.4.1
adobecommerce
2.4.1:ext-1
adobecommerce
2.4.1:ext-2
adobecommerce
2.4.1:ext-3
adobecommerce
2.4.1:ext-4
adobecommerce
2.4.2
adobecommerce
2.4.2:ext-1
adobecommerce
2.4.2:ext-2
adobecommerce
2.4.2:ext-3
adobecommerce
2.4.2:ext-4
adobecommerce
2.4.3
adobecommerce
2.4.3:ext-1
adobecommerce
2.4.3:ext-2
adobecommerce
2.4.3:ext-3
adobecommerce
2.4.3:ext-4
adobecommerce
2.4.4
adobecommerce
2.4.4:p1
adobecommerce
2.4.4:p2
adobecommerce
2.4.4:p3
adobecommerce
2.4.4:p4
adobecommerce
2.4.4:p5
adobecommerce
2.4.5
adobecommerce
2.4.5:p1
adobecommerce
2.4.5:p2
adobecommerce
2.4.5:p3
adobecommerce
2.4.5:p4
adobecommerce
2.4.5:p5
adobecommerce
2.4.6
adobecommerce
2.4.6:p1
adobecommerce
2.4.6:p2
adobecommerce
2.4.7:b1
adobemagento
2.4.4
adobemagento
2.4.4:p1
adobemagento
2.4.4:p2
adobemagento
2.4.4:p3
adobemagento
2.4.5
adobemagento
2.4.5:p1
adobemagento
2.4.5:p2
adobemagento
2.4.5:p3
adobemagento
2.4.5:p4
adobemagento
2.4.6
adobemagento
2.4.6:p1
adobemagento
2.4.6:p2
adobemagento
2.4.7:b1
𝑥
= Vulnerable software versions