CVE-2022-24086
Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
9
*Multiple Sources
Exploited in Wild
Yes
*KEV
Decision
-
*SSVC
Descriptions
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
Adobe Commerce versiones 2.4.3-p1 (y anteriores) y 2.3.7-p2 (y anteriores), están afectadas por una vulnerabilidad de comprobación de entrada inapropiada durante el proceso de compra. Una explotación de este problema no requiere la interacción del usuario y podría resultar en una ejecución de código arbitrario
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-01-27 CVE Reserved
- 2022-02-15 Exploited in Wild
- 2022-02-16 CVE Published
- 2022-02-26 First Exploit
- 2022-03-01 KEV Due Date
- 2024-09-17 CVE Updated
- 2024-11-01 EPSS Updated
CWE
- CWE-20: Improper Input Validation
CAPEC
References (10)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/Mr-xn/CVE-2022-24086 | 2022-12-16 | |
https://github.com/oK0mo/CVE-2022-24086-RCE-PoC | 2022-08-06 | |
https://github.com/nanaao/CVE-2022-24086-RCE | 2022-02-26 | |
https://github.com/pescepilota/CVE-2022-24086 | 2022-12-20 | |
https://github.com/NHPT/CVE-2022-24086-RCE | 2022-03-15 | |
https://github.com/akr3ch/CVE-2022-24086 | 2022-10-01 | |
https://github.com/rxerium/CVE-2022-24086 | 2024-03-18 | |
https://github.com/BurpRoot/CVE-2022-24086 | 2023-09-03 | |
https://github.com/seymanurmutlu/CVE-2022-24086-CVE-2022-24087 | 2022-06-12 |
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/magento/apsb22-12.html | 2022-02-22 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | < 2.3.0 Search vendor "Adobe" for product "Commerce" and version " < 2.3.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | > 2.3.3 <= 2.3.6 Search vendor "Adobe" for product "Commerce" and version " > 2.3.3 <= 2.3.6" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | >= 2.4.0 <= 2.4.2 Search vendor "Adobe" for product "Commerce" and version " >= 2.4.0 <= 2.4.2" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.3.7 Search vendor "Adobe" for product "Commerce" and version "2.3.7" | p1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.3.7 Search vendor "Adobe" for product "Commerce" and version "2.3.7" | p2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.3 Search vendor "Adobe" for product "Commerce" and version "2.4.3" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.3 Search vendor "Adobe" for product "Commerce" and version "2.4.3" | p1 |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | < 2.3.0 Search vendor "Magento" for product "Magento" and version " < 2.3.0" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | > 2.3.3 <= 2.3.6 Search vendor "Magento" for product "Magento" and version " > 2.3.3 <= 2.3.6" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | >= 2.4.0 <= 2.4.2 Search vendor "Magento" for product "Magento" and version " >= 2.4.0 <= 2.4.2" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.3.7 Search vendor "Magento" for product "Magento" and version "2.3.7" | p1, commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.3.7 Search vendor "Magento" for product "Magento" and version "2.3.7" | p2, commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.3 Search vendor "Magento" for product "Magento" and version "2.4.3" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.3 Search vendor "Magento" for product "Magento" and version "2.4.3" | p1, commerce |
Affected
|