High severityNVD Advisory· Published Aug 14, 2024· Updated Aug 14, 2024
Stored XSS through Webhook module public key configuration
CVE-2024-39403
Description
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Confidentiality impact is high due to the attacker being able to exfiltrate sensitive information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
magento/project-community-editionPackagist | <= 2.0.2 | — |
magento/community-editionPackagist | >= 2.4.7-beta1, < 2.4.7-p2 | 2.4.7-p2 |
magento/community-editionPackagist | >= 2.4.6-p1, < 2.4.6-p7 | 2.4.6-p7 |
magento/community-editionPackagist | >= 2.4.5-p1, < 2.4.5-p9 | 2.4.5-p9 |
magento/community-editionPackagist | >= 2.4.4-p1, < 2.4.4-p10 | 2.4.4-p10 |
Affected products
3- ghsa-coords2 versions
>= 2.4.7-beta1, < 2.4.7-p2+ 1 more
- (no CPE)range: >= 2.4.7-beta1, < 2.4.7-p2
- (no CPE)range: <= 2.0.2
- Range: 0
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-mmp7-8cg4-9wrgghsaADVISORY
- helpx.adobe.com/security/products/magento/apsb24-61.htmlghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-39403ghsaADVISORY
News mentions
0No linked articles in our index yet.