VDB

GCVE-110-NCSC-2024-402

GCVE-110-NCSC-2024-402
Advisory PublishedCVSS 9.8/10
Vulnetix · Advisory published October 9, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Weaknesses (CWE)

CWE-918Server-Side Request Forgery (SSRF)CWE-287Improper AuthenticationCWE-284Improper Access ControlCWE-367Time-of-check Time-of-use (TOCTOU) Race ConditionCWE-863Incorrect AuthorizationCWE-285Improper AuthorizationCWE-200Exposure of Sensitive Information to an Unauthorized Actor

Risk Scores

CVSS 3.1
9.8/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
adobemagento__2.4.5-p10
adobemagento_open_source
adobeadobe_commerce_b2b
adobemagento__2.4.7-p3
adobemagento__2.4.6-p8
adobemagento__2.4.4-p11
adobeadobe_commerce

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,198 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›