QID 730359

Date Published: 2022-02-21

QID 730359: Magento Commerce Improper Input Validation (APSB22-12)

The vulnerability exists due to improper input validation. A remote attacker can send a specially crafted request to the application and execute arbitrary code on the target system.

Affected versions:
Adobe Commerce and Magento Open Source 2.4.3-p1 and earlier versions
Adobe Commerce and Magento Open Source 2.3.7-p2 and earlier versions
*Excluding 2.3.0-2.3.3

QID Detection Logic (Unauthenticated):
The detection uses Blind Elephant for fingerprinting Magento Open Source versions.

The vulnerability allows a remote attacker to execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    The issue has been patched in versions after 2.3.7-p2 and 2.4.3-p1

    NOTE: The version number will not change after applying the patches and will still be detected as vulnerable.Workaround:
    Apply Security updates available for Adobe Commerce APSB22-12 to your installation manually if you are unable to upgrade.

    Vendor References

    CVEs related to QID 730359

    Software Advisories
    Advisory ID Software Component Link
    APSB22-12 URL Logo support.magento.com/hc/en-us/articles/4426353041293-Security-updates-available-for-Adobe-Commerce-APSB22-12