Количество 3
Количество 3
CVE-2025-24419
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to modify select data. Exploitation of this issue does not require user interaction.
GHSA-68fp-23v5-2qjg
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to perform actions with permissions that were not granted. Exploitation of this issue does not require user interaction.
BDU:2025-02422
Уязвимость программной платформы для разработки и управления онлайн магазинами Adobe Commerce B2B, связанная с недостатками механизма авторизации, позволяющая нарушителю обойти существующие ограничения безопасности
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-24419 Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to modify select data. Exploitation of this issue does not require user interaction. | CVSS3: 4.3 | 0% Низкий | 12 месяцев назад | |
GHSA-68fp-23v5-2qjg Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to perform actions with permissions that were not granted. Exploitation of this issue does not require user interaction. | CVSS3: 4.3 | 0% Низкий | 12 месяцев назад | |
BDU:2025-02422 Уязвимость программной платформы для разработки и управления онлайн магазинами Adobe Commerce B2B, связанная с недостатками механизма авторизации, позволяющая нарушителю обойти существующие ограничения безопасности | CVSS3: 4.3 | 0% Низкий | 12 месяцев назад |
Уязвимостей на страницу