Description
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution. Exploitation of this issue does not require user interaction.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cj7w-pm77-hvg6 | Magento XML Injection vulnerability in the Widgets Module |
References
History
Wed, 23 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2025-04-23T17:49:38.846Z
Reserved: 2022-06-21T00:00:00.000Z
Link: CVE-2022-34253
Updated: 2024-08-03T09:07:15.462Z
Status : Modified
Published: 2022-08-16T21:15:09.973
Modified: 2024-11-21T07:09:09.320
Link: CVE-2022-34253
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA