Adobe Commerce checkout improper input validation leads to remote code execution
100Vexday Risk Score
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
ssvc Actcvss 9.8epss 99%
from disclosure to weapon4 days
Published on NVDFeb 16
1st PoC+4d
CISA KEVFeb 15
exploitation probability
99%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
13 public exploit(s)
Action required by CISAfederal deadline: 2022-03-01
Apply updates per vendor instructions.
Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Adobe · Magento Commercepublic PoCs found — 13
githubgithub.com/Mr-xn/CVE-2022-24086★ 35githubgithub.com/pescepilota/CVE-2022-24086★ 6githubgithub.com/oK0mo/CVE-2022-24086-RCE-PoC★ 6githubgithub.com/akr3ch/CVE-2022-24086★ 2githubgithub.com/seymanurmutlu/CVE-2022-24086-CVE-2022-24087★ 2githubgithub.com/BurpRoot/CVE-2022-24086★ 0githubgithub.com/wubinworks/magento2-template-filter-patch★ 0githubgithub.com/NHPT/CVE-2022-24086-RCE★ 0githubgithub.com/nanaao/CVE-2022-24086-RCE★ 0vulncheckvulncheck.com/xdb/44b62a8bb94bunverifiedvulncheckvulncheck.com/xdb/a001349657caunverifiedvulncheckvulncheck.com/xdb/b307483bd289unverifiedvulncheckvulncheck.com/xdb/7d60b3d01025unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.