QID 730439

Date Published: 2022-06-13

QID 730439: Magento Commerce Arbitrary Code Execution Vulnerability (APSB22-13)

Magento Open Source delivers all the basic ecommerce capabilities and allows you to build a unique online store from the ground up.

Affected versions:
Adobe Commerce and Magento Open Source 2.4.3-p1 and earlier versions
Adobe Commerce and Magento Open Source 2.3.7-p2 and earlier versions

QID Detection Logic (Unauthenticated):
The detection uses Blind Elephant for fingerprinting Magento Open Source versions.

Successful exploitation of this vulnerability may allow an authenticated attacker to execute arbitrary code on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    The issue has been patched. Customers are advised to refer APSB22-13 Advisoryfor further patch information.

    Vendor References

    CVEs related to QID 730439

    Software Advisories
    Advisory ID Software Component Link
    APSB22-13 URL Logo helpx.adobe.com/security/products/magento/apsb22-13.html