Описание
Magento Community Edition Improper Input Validation vulnerability
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact to high. Exploitation of this issue does not require user interaction.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-54236
- https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397
- https://helpx.adobe.com/security/products/magento/apsb25-88.html
- https://nullsecurityx.codes/cve-2025-54236-sessionreaper-unauthenticated-rce-in-magento
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-54236
Пакеты
magento/community-edition
<= 2.4.5-p14
Отсутствует
magento/community-edition
= 2.4.6
Отсутствует
magento/community-edition
>= 2.4.6-p1, <= 2.4.6-p12
Отсутствует
magento/community-edition
= 2.4.5
Отсутствует
magento/community-edition
>= 2.4.9-alpha1, <= 2.4.9-alpha2
Отсутствует
magento/community-edition
= 2.4.7
Отсутствует
magento/community-edition
= 2.4.8
Отсутствует
magento/community-edition
>= 2.4.7-beta1, <= 2.4.7-p7
Отсутствует
magento/community-edition
>= 2.4.8-beta1, <= 2.4.8-p2
Отсутствует
magento/community-edition
= 2.4.9
Отсутствует
magento/project-community-edition
<= 2.0.2
Отсутствует
Связанные уязвимости
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
Уязвимость компонента Siemens User Management Component (UMC) веб-системы управления технологическими процессами SIMATIC PCS neo, позволяющая нарушителю выполнить произвольный код