← back
CVE-2024-39400

DOM XSS through integrations can impact other admins

CVSS 8.1 HIGHEPSS 0.6%CWE-79
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.1EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
14 Aug 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an admin attacker to inject and execute arbitrary JavaScript code within the context of the user's browser session. Exploitation of this issue requires user interaction, such as convincing a victim to click on a malicious link. Confidentiality and integrity impact is high as it affects other admin accounts.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
Affected products
Adobe · Adobe Commerce

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →