Description
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to trick a victim into performing actions they did not intend to do, which could be used to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction, typically in the form of the victim clicking a link or visiting a malicious website.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-18433 | Magento Open Source allows Cross-Site Request Forgery (CSRF) |
Github GHSA |
GHSA-hqgj-4396-hmxv | Magento Open Source allows Cross-Site Request Forgery (CSRF) |
References
History
No history.
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-08-01T21:59:42.943Z
Reserved: 2023-12-04T16:52:22.968Z
Link: CVE-2024-20718
Updated: 2024-08-01T21:59:42.943Z
Status : Modified
Published: 2024-02-15T14:15:45.870
Modified: 2024-11-21T08:53:00.647
Link: CVE-2024-20718
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA