CVE-2025-24438 Information
Feb 12, 2025
cve
Description
Adobe Commerce versions 2.4.7-beta1 2.4.7-p3 2.4.6-p8 2.4.5-p10 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover increasing the confidentiality and integrity impact as high.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Reference
https://helpx.adobe.com/security/products/magento/apsb25-08.html
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
8.7
Related CNNVD
CNNVD-202506-2791 (Published: 2025-06-20)
Share on: