CVE-2025-24415

CVSS 3.1 Score 8.7 of 10 (high)

Details

Published Feb 11, 2025
Updated: Feb 27, 2025
CWE ID 79

Summary

CVE-2025-24415 is a stored Cross-Site Scripting (XSS) vulnerability affecting Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, and earlier. This issue allows a low-privileged attacker to inject malicious scripts into vulnerable form fields. When a victim browses to the affected page, the malicious JavaScript code is executed in their browser, increasing the risk of session takeover. Confidentiality and integrity are significantly impacted as a result.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share