Description
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into every admin page. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field, that could be leveraged to gain admin access.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-18434 | Magento Open Source allows Cross-Site Scripting (XSS) |
Github GHSA |
GHSA-264g-f7v8-q5qq | Magento Open Source allows Cross-Site Scripting (XSS) |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-08-01T21:59:42.947Z
Reserved: 2023-12-04T16:52:22.968Z
Link: CVE-2024-20719
Updated: 2024-08-01T21:59:42.947Z
Status : Modified
Published: 2024-02-15T14:15:46.077
Modified: 2024-11-21T08:53:00.843
Link: CVE-2024-20719
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA