Executive brief
Adobe Commerce and Magento Open Source are vulnerable to improper input validation during the checkout process. This flaw allows a remote, unauthenticated attacker to execute arbitrary code without any user interaction.
Affected products
- Adobe Commerce 2.4.3-p1 (and earlier), 2.3.7-p2 (and earlier)
- Adobe Magento Open Source 2.4.3-p1 (and earlier), 2.3.7-p2 (and earlier)
Timeline
- 2022-02-15: disclosed
- 2022-02-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-02-16: advisory: NVD Published Date
- 2022-02-15: exploited: Reported as exploited in the wild at time of publication.