Junglewise Threat Intelligence

CVE-2022-24086: Magento improper input validation vulnerability

CVE-2022-24086 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-02-17

Technologies: Adobe Commerce, Adobe Magento Open Source. Vendors: Adobe.

Executive brief

Adobe Commerce and Magento Open Source are vulnerable to improper input validation during the checkout process. This flaw allows a remote, unauthenticated attacker to execute arbitrary code without any user interaction.

Affected products

  • Adobe Commerce 2.4.3-p1 (and earlier), 2.3.7-p2 (and earlier)
  • Adobe Magento Open Source 2.4.3-p1 (and earlier), 2.3.7-p2 (and earlier)

Timeline

  • 2022-02-15: disclosed
  • 2022-02-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-02-16: advisory: NVD Published Date
  • 2022-02-15: exploited: Reported as exploited in the wild at time of publication.

Related threats