Impact
Adobe Commerce, its B2B extension, Webhooks Plugin and Magento Open Source are vulnerable to an SQL injection caused by improper neutralization of special characters. An attacker who can send specially crafted requests can execute arbitrary SQL commands in the context of the current user. This could lead to elevated privileges, account takeover, or arbitrary code execution, and the vulnerability does not require any user interaction.
Affected Systems
The affected vendors are Adobe, with products Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin and Magento Open Source. No specific version range is supplied in the data, so all current releases may be vulnerable until a fix is available.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity, while an EPSS score of 20% shows a relatively high probability of exploitation. The vulnerability is listed outside the CISA KEV catalog. Attackers can exploit it by sending crafted HTTP requests that are processed as SQL code, bypassing any user interaction requirement.
OpenCVE Enrichment