VDB

GCVE-110-NCSC-2024-348

GCVE-110-NCSC-2024-348
Advisory PublishedCVSS 9.0/10
Vulnetix · Advisory published August 14, 2024
Adobe heeft kwetsbaarheden verholpen in Commerce en Magento.

Weaknesses (CWE)

CWE-434Unrestricted Upload of File with Dangerous TypeCWE-307Improper Restriction of Excessive Authentication AttemptsCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-284Improper Access ControlCWE-863Incorrect AuthorizationCWE-352Cross-Site Request Forgery (CSRF)CWE-285Improper Authorization

Risk Scores

CVSS 3.1
9.0/10
Critical · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
adobemagento_open_source
adobeadobe_commerce

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

75,704 records in the GCVE database · Updated August 1, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›