CVE-2025-27189
08.04.2025, 21:15
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could be exploited to cause a denial-of-service condition. An attacker could trick a logged-in user into submitting a forged request to the vulnerable application, which may disrupt service availability. Exploitation of this issue requires user interaction, typically in the form of clicking a malicious link or visiting an attacker-controlled website.
Vendor | Product | Version |
---|---|---|
adobe | commerce_b2b | 𝑥 < 1.3.3 |
adobe | commerce_b2b | 1.3.3 |
adobe | commerce_b2b | 1.3.3:p10 |
adobe | commerce_b2b | 1.3.3:p11 |
adobe | commerce_b2b | 1.3.3:p12 |
adobe | commerce_b2b | 1.3.4 |
adobe | commerce_b2b | 1.3.4:p10 |
adobe | commerce_b2b | 1.3.4:p11 |
adobe | commerce_b2b | 1.3.4:p9 |
adobe | commerce_b2b | 1.3.5 |
adobe | commerce_b2b | 1.3.5:p7 |
adobe | commerce_b2b | 1.3.5:p8 |
adobe | commerce_b2b | 1.3.5:p9 |
adobe | commerce_b2b | 1.4.2 |
adobe | commerce_b2b | 1.4.2:p1 |
adobe | commerce_b2b | 1.4.2:p2 |
adobe | commerce_b2b | 1.4.2:p3 |
adobe | commerce_b2b | 1.4.2:p4 |
adobe | commerce_b2b | 1.5.0 |
adobe | commerce_b2b | 1.5.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration