Unrated severityNVD Advisory· Published Jun 13, 2024· Updated Aug 2, 2024
RCE in the Adobe Commerce Webhook module through a legit webhook definition
CVE-2024-34110
Description
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. A high-privilege attacker could exploit this vulnerability by uploading a malicious file to the system, which could then be executed. Exploitation of this issue does not require user interaction.
Affected products
2- Adobe/Adobe Commercev5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- helpx.adobe.com/security/products/magento/apsb24-40.htmlmitrevendor-advisory
News mentions
0No linked articles in our index yet.