We found results for “”
CVE-2024-20717
Good to know:
Date: February 15, 2024
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix
Upgrade Version
Upgrade to version magento/community-edition - 2.4.4-p7;magento/community-edition - dev-2.4.3-patch-34184;magento/community-edition - 2.4.5-p6;magento/community-edition - dev-lenaorobei-patch-2;magento/community-edition - 2.4.6-p4;magento/community-edition - dev-ihor-sviziev-patch-1;magento/community-edition - 2.4.5-p10;magento/community-edition - dev-2.4.2-regression;magento/community-edition - 2.4.4-p10;magento/community-edition - dev-2.4-addressing-discriminatory-language;magento/community-edition - dev-2.3.7-patch-33664;magento/community-edition - dev-converted-magento-magento2-2.4.3
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | LOW |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


