Описание
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Ссылки
- PatchVendor Advisory
- US Government Resource
Уязвимые конфигурации
Одно из
Одно из
Одно из
EPSS
10 Critical
CVSS3
Дефекты
Связанные уязвимости
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Уязвимость прикладного программного интерфейса программных платформ для разработки и управления онлайн магазинами Magento Open Source, Adobe Commerce и Adobe Commerce B2B, позволяющая нарушителю выполнить произвольный код
EPSS
10 Critical
CVSS3