QID 730622

QID 730622: Adobe Magento Arbitrary Code Execution Vulnerability (APSB22-48)

Magento Open Source delivers all the basic ecommerce capabilities and allows you to build a unique online store from the ground up.

Affected versions:
Adobe Commerce and Magento Open Source 2.4.4-p1 and earlier versions
Adobe Commerce and Magento Open Source 2.4.5 and earlier versions

QID Detection Logic (Unauthenticated):
The detection uses Blind Elephant for fingerprinting Magento Open Source versions.

Successful exploitation could lead to arbitrary code execution.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    The issue has been patched. Customers are advised to refer APSB22-48 Advisoryfor further patch information.

    CVEs related to QID 730622

    Software Advisories
    Advisory ID Software Component Link
    APSB22-48 URL Logo helpx.adobe.com/security/products/magento/apsb22-48.html