CVE-2022-24086
CRITICAL KEV NUCLEIAdobe Commerce <2.4.3-p1, <2.3.7-p2 - RCE
Title source: llmDescription
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
Exploits (10)
nomisec
WRITEUP
2 stars
by seymanurmutlu · poc
https://github.com/seymanurmutlu/CVE-2022-24086-CVE-2022-24087
nomisec
WORKING POC
by wubinworks · poc
https://github.com/wubinworks/magento2-template-filter-patch
Nuclei Templates (1)
Adobe Commerce (Magento) - Remote Code Execution
CRITICALVERIFIEDby daffainfo
Shodan:
X-Magento-Tags
Scores
CVSS v3
9.8
EPSS
0.9350
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2022-02-15
VulnCheck KEV
2022-02-14
InTheWild.io
2022-02-14
ENISA EUVD
EUVD-2022-0975
Classification
CWE
CWE-20
Status
published
Affected Products (11)
adobe/commerce
< 2.3.0
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/magento
< 2.3.0
adobe/magento
adobe/magento
adobe/magento
adobe/magento
magento/community-edition
< 2.3.7-p3Packagist
Timeline
Published
Feb 16, 2022
KEV Added
Feb 15, 2022
Tracked Since
Feb 18, 2026