CVE-2024-45148

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 10, 2024
Updated: Oct 16, 2024
CWE ID 287

Summary

CVE-2024-45148 is a newly disclosed vulnerability affecting Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier. This issue represents an Improper Authentication vulnerability, enabling a low-privileged attacker to bypass security features and gain unauthorized access without requiring user interaction or proper credentials. The exploitation of this vulnerability does not depend on any user engagement, posing a significant risk to affected systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share