Описание
Magento stored Cross-Site Scripting (XSS) vulnerability
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Пакеты
magento/community-edition
>= 2.4.7-beta1, < 2.4.7-p4
2.4.7-p4
magento/community-edition
>= 2.4.6-p1, < 2.4.6-p9
2.4.6-p9
magento/community-edition
>= 2.4.5-p1, < 2.4.5-p11
2.4.5-p11
magento/community-edition
< 2.4.4-p12
2.4.4-p12
magento/community-edition
= 2.4.7
Отсутствует
magento/community-edition
= 2.4.6
Отсутствует
magento/community-edition
= 2.4.5
Отсутствует
magento/community-edition
= 2.4.4
Отсутствует
magento/community-edition
= 2.4.8-beta1
Отсутствует
magento/project-community-edition
<= 2.0.2
Отсутствует
Связанные уязвимости
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Уязвимость программных платформ для разработки и управления онлайн магазинами Magento Open Source, Adobe Commerce и Adobe Commerce B2B, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный код