Impact
Improper Encoding or Escaping of Output allows an attacker to inject malicious payloads that the application renders without proper sanitization, leading to arbitrary code execution in the current user’s context. The flaw is scope‑altering and does not require user interaction, enabling a remote attacker to trigger exploitation through crafted HTTP requests or API calls.
Affected Systems
Affected products include Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source. The advisory does not disclose specific version information, so any release that contains the unencoded output handling is potentially at risk.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity, while the EPSS score of 2% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation can occur remotely without user interaction, meaning an attacker with network access to the affected application could trigger code execution by sending crafted requests in the context of the current user.
OpenCVE Enrichment