VDB
GCVE-110-NCSC-2024-348
GCVE-110-NCSC-2024-348
Advisory PublishedCVSS 9.0/10
Adobe heeft kwetsbaarheden verholpen in Commerce en Magento.
Weaknesses (CWE)
CWE-434Unrestricted Upload of File with Dangerous TypeCWE-307Improper Restriction of Excessive Authentication AttemptsCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-284Improper Access ControlCWE-863Incorrect AuthorizationCWE-352Cross-Site Request Forgery (CSRF)CWE-285Improper Authorization
Risk Scores
CVSS 3.1
9.0/10
Critical · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| adobe | magento_open_source | — | — |
| adobe | adobe_commerce | — | — |
Aliases
CVE-2024-39397CVE-2024-39398CVE-2024-39399CVE-2024-39400CVE-2024-39401CVE-2024-39402CVE-2024-39403CVE-2024-39404CVE-2024-39405CVE-2024-39406CVE-2024-39407CVE-2024-39408CVE-2024-39409CVE-2024-39410CVE-2024-39411CVE-2024-39412CVE-2024-39413CVE-2024-39414CVE-2024-39415CVE-2024-39416CVE-2024-39417CVE-2024-39418CVE-2024-39419
Browse GCVE Records
75,704 records in the GCVE database · Updated August 1, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.