Skip to main content

Vendors Actively Bypass Security Patch for Year-Old Magento Vulnerability


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

By Ionut Arghire on January 18, 2023

 

Vendors and agencies are actively bypassing the security patch that Adobe released in February 2022 to address CVE-2022-24086, a critical mail template vulnerability in Adobe Commerce and Magento stores, ecommerce security firm Sansec warns.

The CVE-2022-24086 bug (CVSS score of 9.8) is described as an improper input validation bug in the checkout process. It could be exploited to achieve arbitrary code execution, with in-the-wild exploitation observed roughly one week after patches were made available for it.

 

>> Full Article <<

0 replies

Be the first to reply!

Reply