CRITICAL🇵🇱 Wersja polska

CVE-2025-24434

CVSS 9.1v3.1pub. 2025-02-11upd. 2025-04-16

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.

🤖 AI Analysis
How it works

The vulnerability results from improper authorization verification in Adobe Commerce. An attacker can remotely bypass access control mechanisms without needing to own an account or engage the victim. After successfully exploiting the flaw, it is possible to hijack another user's session (session takeover), which translates to gaining full control over their account and data.

Impact

An attacker can gain unauthorized access to other users' accounts by hijacking their sessions, resulting in a breach of confidentiality and data integrity within the Adobe Commerce platform.

Mitigation & patch

Apply patches available from the vendor according to references: https://helpx.adobe.com/security/products/magento/apsb25-08.html

Who is affected

Adobe Commerce in versions: 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, and earlier.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Adobe Commerce

    APP
    Adobe
    2.4.42.4.52.4.62.4.72.4.8
  • Adobe Commerce B2b

    APP
    Adobe
    1.3.31.3.41.3.51.4.21.5.0
  • Adobe Magento

    APP
    Adobe
    2.4.42.4.52.4.62.4.72.4.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2025-54236CRITICAL9.1⚠ KEVPL ✓same product

Adobe Commerce/Magento — przejęcie sesji przez Improper Input Validation

CVE-2024-34102CRITICAL9.8⚠ KEVPL ✓same product

Krytyczna podatność XXE w Adobe Commerce umożliwiająca RCE

CVE-2022-24086CRITICAL9.8⚠ KEVPL ✓same product

Adobe Commerce — RCE przez błędną walidację danych podczas checkout

CVE-2026-48356CRITICAL9.3PL ✓same product

Adobe Commerce — nieograniczony upload pliku umożliwiający RCE

CVE-2026-48358CRITICAL9.1PL ✓same product

RCE w Adobe Commerce — błąd kodowania wyjścia (CVE-2026-48358)