CVE-2022-24086

CRITICAL KEV NUCLEI

Adobe Commerce <2.4.3-p1, <2.3.7-p2 - RCE

Title source: llm

Description

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

Exploits (10)

nomisec WRITEUP 36 stars
by Mr-xn · infoleak
https://github.com/Mr-xn/CVE-2022-24086
nomisec WRITEUP 7 stars
by oK0mo · poc
https://github.com/oK0mo/CVE-2022-24086-RCE-PoC
nomisec WORKING POC 5 stars
by pescepilota · remote
https://github.com/pescepilota/CVE-2022-24086
nomisec WORKING POC 2 stars
by akr3ch · poc
https://github.com/akr3ch/CVE-2022-24086
nomisec WRITEUP 2 stars
by seymanurmutlu · poc
https://github.com/seymanurmutlu/CVE-2022-24086-CVE-2022-24087
nomisec SUSPICIOUS
by NHPT · poc
https://github.com/NHPT/CVE-2022-24086-RCE
github FAILED
by iitsmel · htmlpoc
https://github.com/iitsmel/Research/tree/main/CVE-2022-24086
nomisec WORKING POC
by wubinworks · poc
https://github.com/wubinworks/magento2-template-filter-patch
nomisec WRITEUP
by BurpRoot · remote
https://github.com/BurpRoot/CVE-2022-24086
nomisec WRITEUP
by nanaao · remote
https://github.com/nanaao/CVE-2022-24086-RCE

Nuclei Templates (1)

Adobe Commerce (Magento) - Remote Code Execution
CRITICALVERIFIEDby daffainfo
Shodan: X-Magento-Tags

Scores

CVSS v3 9.8
EPSS 0.9350
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2022-02-15
VulnCheck KEV 2022-02-14
InTheWild.io 2022-02-14
ENISA EUVD EUVD-2022-0975

Classification

CWE
CWE-20
Status published

Affected Products (11)

adobe/commerce < 2.3.0
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/magento < 2.3.0
adobe/magento
adobe/magento
adobe/magento
adobe/magento
magento/community-edition < 2.3.7-p3Packagist

Timeline

Published Feb 16, 2022
KEV Added Feb 15, 2022
Tracked Since Feb 18, 2026