CVE-2023-22247

HIGH

Adobe Commerce <2.4.4-p2, 2.4.5-p1 - XML Injection

Title source: llm
STIX 2.1

Description

Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An unauthenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.

Scores

CVSS v3 7.5
EPSS 0.0477
EPSS Percentile 89.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-91
Status published
Products (8)
adobe/commerce 2.4.4 (3 CPE variants)
adobe/commerce 2.4.5 (2 CPE variants)
adobe/commerce < 2.4.4
adobe/magento_open_source 2.4.4 (3 CPE variants)
adobe/magento_open_source 2.4.5 (2 CPE variants)
adobe/magento_open_source < 2.4.4
magento/community-edition 2.4.5-p1 - 2.4.5-p2Packagist
magento/project-community-edition 0Packagist
Published Mar 27, 2023
Tracked Since Feb 18, 2026