QID 730759

QID 730759: Adobe Commerce Multiple Security Vulnerabilities (APSB23-17)

Magento Open Source delivers all the basic ecommerce capabilities and allows you to build a unique online store from the ground up.

Affected versions:
Adobe Commerce and Magento Open Source 2.4.4-p2 and earlier versions
Adobe Commerce and Magento Open Source 2.4.5-p1 and earlier versions

QID Detection Logic (Unauthenticated):
The detection uses Blind Elephant for fingerprinting Magento Open Source versions.

Successful exploitation could lead to arbitrary code execution, security feature bypass and arbitrary file system read.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    The issue has been patched. Customers are advised to refer APSB23-17 Advisoryfor further patch information.

    CVEs related to QID 730759

    Software Advisories
    Advisory ID Software Component Link
    APSB23-17 URL Logo helpx.adobe.com/security/products/magento/apsb23-17.html