QID 730359
Date Published: 2022-02-21
QID 730359: Magento Commerce Improper Input Validation (APSB22-12)
The vulnerability exists due to improper input validation. A remote attacker can send a specially crafted request to the application and execute arbitrary code on the target system.
Affected versions:
Adobe Commerce and Magento Open Source 2.4.3-p1 and earlier versions
Adobe Commerce and Magento Open Source 2.3.7-p2 and earlier versions
*Excluding 2.3.0-2.3.3
QID Detection Logic (Unauthenticated):
The detection uses Blind Elephant for fingerprinting Magento Open Source versions.
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
NOTE: The version number will not change after applying the patches and will still be detected as vulnerable.Workaround:
Apply Security updates available for Adobe Commerce APSB22-12 to your installation manually if you are unable to upgrade.
- Magento Commerce -
helpx.adobe.com/security/products/magento/apsb22-12.html
CVEs related to QID 730359
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| APSB22-12 |
|