QID 730591

Date Published: 2022-08-23

QID 730591: Adobe Magento Arbitrary Code Execution Vulnerability (APSB22-38)

Magento Open Source delivers all the basic ecommerce capabilities and allows you to build a unique online store from the ground up.

Affected versions:
Adobe Commerce and Magento Open Source 2.4.3-p2 and earlier versions
Adobe Commerce and Magento Open Source 2.3.7-p3 and earlier versions
Adobe Commerce and Magento Open Source 2.4.4 and earlier versions

QID Detection Logic (Unauthenticated):
The detection uses Blind Elephant for fingerprinting Magento Open Source versions.

Successful exploitation could lead to arbitrary code execution, privilege escalation and security feature bypass.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    The issue has been patched. Customers are advised to refer APSB22-38 Advisoryfor further patch information.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    APSB22-38 URL Logo helpx.adobe.com/security/products/magento/apsb22-38.html