Moderate severityNVD Advisory· Published Aug 14, 2024· Updated Sep 16, 2024
Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)
CVE-2024-39408
Description
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changeson behalf of a user. The vulnerability could be exploited by tricking a victim into clicking a link or loading a page that submits a malicious request. Exploitation of this issue requires user interaction.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
magento/community-editionPackagist | >= 2.4.7-p1, < 2.4.7-p2 | 2.4.7-p2 |
magento/community-editionPackagist | >= 2.4.6-p1, < 2.4.6-p7 | 2.4.6-p7 |
magento/community-editionPackagist | >= 2.4.5-p1, < 2.4.5-p9 | 2.4.5-p9 |
magento/community-editionPackagist | < 2.4.4-p10 | 2.4.4-p10 |
Affected products
2- Range: 0
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-4cj6-f32v-6hgxghsaADVISORY
- helpx.adobe.com/security/products/magento/apsb24-61.htmlghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-39408ghsaADVISORY
News mentions
0No linked articles in our index yet.