QID 997885

Date Published: 2024-04-01

QID 997885: PHP (Composer) Security Update for magento/community-edition (GHSA-f8fv-f786-9933)

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Refer to Github security advisory GHSA-f8fv-f786-9933 for updates and patch information.
    Vendor References

    CVEs related to QID 997885

    Software Advisories
    Advisory ID Software Component Link
    GHSA-f8fv-f786-9933 magento/community-edition URL Logo github.com/advisories/GHSA-f8fv-f786-9933