CVE-2022-24086

CVE Published 2022-02-16
Related CWE(s) CWE-20: Improper Input Validation
Related Vendor(s) adobe, magento
Related Product(s) magento, commerce
Exploitation Reported (CISA KEV) 2022-02-15
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Threat Reports Related to CVE-2022-24086

Report

Magnet Goblin Targets Publicly Facing Servers Using 1-Day Vulnerabilities - Check Point Research

This blog post from CheckPoint Research describes a campaign targeting Ivanti, Magento, Qlink Sense and possibly Apache ActiveMQ systems which ...

Associated CAPEC Patterns

References