CVE-2024-45128
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-45128 is a newly disclosed vulnerability affecting Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10, and earlier. This issue involves an Improper Authorization vulnerability, which enables a low-privileged attacker to bypass security measures without requiring user interaction. The impact of this vulnerability on integrity and availability is considered low. However, successful exploitation could allow an attacker to gain unauthorized access to restricted areas of the affected system. It is crucial for Adobe Commerce users to apply the necessary patches as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Adobe Commerce
Affected Vendors
- Adobe