← back
CVE-2024-20720criticalobserved exploitationCWE-78

Command injection in data collector backup due to insufficient patching of CVE-2023-38208

50Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 9.1epss 3.7%
from disclosure to weapon
Published on NVDFeb 15
VulnCheck+49d
exploitation probability
3.7%top 11% of all CVEs
observed exploitation
yesVulnCheck
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected products
Adobe · Adobe Commerce