VDB
GCVE-110-NCSC-2024-402
GCVE-110-NCSC-2024-402
Advisory PublishedCVSS 9.8/10
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Weaknesses (CWE)
CWE-918Server-Side Request Forgery (SSRF)CWE-287Improper AuthenticationCWE-284Improper Access ControlCWE-367Time-of-check Time-of-use (TOCTOU) Race ConditionCWE-863Incorrect AuthorizationCWE-285Improper AuthorizationCWE-200Exposure of Sensitive Information to an Unauthorized Actor
Risk Scores
CVSS 3.1
9.8/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| adobe | magento__2.4.5-p10 | — | — |
| adobe | magento_open_source | — | — |
| adobe | adobe_commerce_b2b | — | — |
| adobe | magento__2.4.7-p3 | — | — |
| adobe | magento__2.4.6-p8 | — | — |
| adobe | magento__2.4.4-p11 | — | — |
| adobe | adobe_commerce | — | — |
Aliases
CVE-2024-45115CVE-2024-45116CVE-2024-45117CVE-2024-45118CVE-2024-45119CVE-2024-45120CVE-2024-45121CVE-2024-45122CVE-2024-45123CVE-2024-45124CVE-2024-45125CVE-2024-45127CVE-2024-45128CVE-2024-45129CVE-2024-45130CVE-2024-45131CVE-2024-45132CVE-2024-45133CVE-2024-45134CVE-2024-45135CVE-2024-45148CVE-2024-45149
Browse GCVE Records
74,198 records in the GCVE database · Updated July 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.