Description
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
Exploits (10)
nomisec
WRITEUP
2 stars
by seymanurmutlu · poc
https://github.com/seymanurmutlu/CVE-2022-24086-CVE-2022-24087
nomisec
WORKING POC
by wubinworks · poc
https://github.com/wubinworks/magento2-template-filter-patch
Nuclei Templates (1)
Adobe Commerce (Magento) - Remote Code Execution
CRITICALVERIFIEDby daffainfo
Shodan:
X-Magento-Tags
Scores
CVSS v3
9.8
EPSS
0.9360
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Lab Environment
COMMUNITY
Community Lab
+7 more repos
Details
CISA KEV
2022-02-15
VulnCheck KEV
2022-02-14
InTheWild.io
2022-02-14
ENISA EUVD
EUVD-2022-0975
CWE
CWE-20
Status
published
Products (7)
adobe/commerce
2.3.7 p1 (2 CPE variants)
adobe/commerce
2.4.3 (2 CPE variants)
adobe/commerce
< 2.3.0
adobe/magento
2.3.7 p1 (2 CPE variants)
adobe/magento
2.4.3 (2 CPE variants)
adobe/magento
< 2.3.0
magento/community-edition
2.3.3-p1 - 2.3.7-p3Packagist
Published
Feb 16, 2022
KEV Added
Feb 15, 2022
Tracked Since
Feb 18, 2026