CVE-2022-24086

CRITICAL KEV NUCLEI LAB

Adobe Commerce <2.4.3-p1, <2.3.7-p2 - RCE

Title source: llm

Description

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

Exploits (10)

nomisec WRITEUP 36 stars
by Mr-xn · infoleak
https://github.com/Mr-xn/CVE-2022-24086
nomisec WRITEUP 7 stars
by oK0mo · poc
https://github.com/oK0mo/CVE-2022-24086-RCE-PoC
nomisec WORKING POC 5 stars
by pescepilota · remote
https://github.com/pescepilota/CVE-2022-24086
nomisec WORKING POC 2 stars
by akr3ch · poc
https://github.com/akr3ch/CVE-2022-24086
nomisec WRITEUP 2 stars
by seymanurmutlu · poc
https://github.com/seymanurmutlu/CVE-2022-24086-CVE-2022-24087
nomisec WORKING POC
by wubinworks · poc
https://github.com/wubinworks/magento2-template-filter-patch
github FAILED
by iitsmel · htmlpoc
https://github.com/iitsmel/Research/tree/main/CVE-2022-24086
nomisec WRITEUP
by BurpRoot · remote
https://github.com/BurpRoot/CVE-2022-24086
nomisec SUSPICIOUS
by NHPT · poc
https://github.com/NHPT/CVE-2022-24086-RCE
nomisec WRITEUP
by nanaao · remote
https://github.com/nanaao/CVE-2022-24086-RCE

Nuclei Templates (1)

Adobe Commerce (Magento) - Remote Code Execution
CRITICALVERIFIEDby daffainfo
Shodan: X-Magento-Tags

Scores

CVSS v3 9.8
EPSS 0.9360
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull docker.io/bitnami/magento:2.4.3-debian-10-r0
docker pull docker.io/bitnami/elasticsearch:7
+7 more repos

Details

CISA KEV 2022-02-15
VulnCheck KEV 2022-02-14
InTheWild.io 2022-02-14
ENISA EUVD EUVD-2022-0975
CWE
CWE-20
Status published
Products (7)
adobe/commerce 2.3.7 p1 (2 CPE variants)
adobe/commerce 2.4.3 (2 CPE variants)
adobe/commerce < 2.3.0
adobe/magento 2.3.7 p1 (2 CPE variants)
adobe/magento 2.4.3 (2 CPE variants)
adobe/magento < 2.3.0
magento/community-edition 2.3.3-p1 - 2.3.7-p3Packagist
Published Feb 16, 2022
KEV Added Feb 15, 2022
Tracked Since Feb 18, 2026