Back to overview

CVE-2022-35698

CRITICAL
10.0
CVSS 3.1
Description
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.

Metadata

CVE ID
CVE-2022-35698
State
PUBLISHED
Assigner
adobe
Reserved
2022-07-12 00:00 UTC
Published
2022-10-14 19:48 UTC
Last updated
2025-04-23 16:47 UTC
Primary CWE
CWE-79
Cross-site Scripting (Stored XSS) (CWE-79)
Vendor / Product
Adobe / Magento Commerce
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Adobe Magento Commerce unspecified ≤ 2.4.5, unspecified ≤ 2.4.4-p1, unspecified ≤ None
Weakness (CWE)
CWESourceDescription
CWE-79 cna Cross-site Scripting (Stored XSS) (CWE-79)
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview