Adobe Commerce
cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*
- <= 2.4.9
- <= 2.4.8-p5
- <= 2.4.7-p10
- <= 2.4.6-p15
- <= 2.4.5-p17
- <= 2.4.4-p18
A vulnerability allowing improper redirection (open redirect) has been identified in Adobe Commerce. This issue could lead to a security feature bypass, as it allows an attacker to create a malicious URL that redirects a victim to an attacker-controlled site. Such redirection could facilitate credential theft and account takeover. Exploitation of this vulnerability requires user interaction, as the victim must click on the malicious link. The vulnerability affects multiple versions of Adobe Commerce, Adobe Commerce B2B, Magento Open Source, and Adobe Commerce Events.
Exploitation of this vulnerability could result in a security feature bypass, potentially allowing for credential theft and account takeover.
Users are advised to update to the latest versions of Adobe Commerce, Adobe Commerce B2B, Magento Open Source, or Adobe Commerce Events. Instructions for updating can be found in the Adobe Security Bulletin APSB26-73.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.