Adobe Commerce
cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*
- <= 2.4.9
- <= 2.4.8-p5
- <= 2.4.7-p10
- <= 2.4.6-p15
- <= 2.4.5-p17
- <= 2.4.4-p18
A vulnerability allowing unrestricted file uploads of dangerous types has been identified in Adobe Commerce. This issue could lead to arbitrary code execution in the context of the current user. An attacker might exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation requires user interaction, as a victim must visit a maliciously crafted URL or engage with a compromised web page.
Successful exploitation could result in arbitrary code execution, allowing an attacker to execute malicious scripts on the affected system.
Users are advised to update to the latest versions of Adobe Commerce. Instructions for updating can be found in the Adobe Security Bulletin APSB26-73.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.