CVE-2025-27400

CVSS 3.1 Score 2.9 of 10 (low)

Details

Published Feb 28, 2025
CWE ID 79

Summary

CVE-2025-27400 is a vulnerability affecting Magento's Long Term Support (LTS) versions prior to 20.12.3 and 20.13.1. This community-driven project offers an alternative to the Magento Community Edition with high backward compatibility. The flaw allows for script execution in the admin panel, leading to potential cross-site scripting attacks against authenticated admin users. However, the attacker would need an admin user with configuration access, making the likelihood of successful practical exploitation relatively low. Versions 20.12.3 and 20.13.1 have been released with a patch to address this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share