Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adobe magento
|
|
| CPEs | cpe:2.3:a:magento:magento:2.3.7:p1:*:*:commerce:*:*:* cpe:2.3:a:magento:magento:2.3.7:p2:*:*:commerce:*:*:* cpe:2.3:a:magento:magento:2.4.3:-:*:*:commerce:*:*:* cpe:2.3:a:magento:magento:2.4.3:p1:*:*:commerce:*:*:* |
cpe:2.3:a:adobe:magento:*:*:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.3.7:p1:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.3.7:p2:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.3:-:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.3:p1:*:*:open_source:*:*:* |
| Vendors & Products |
Magento
Magento magento |
Adobe magento
|
Wed, 22 Oct 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Feb 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Status: PUBLISHED
Assigner: adobe
Published: 2022-02-16T16:38:28.383Z
Updated: 2025-10-21T23:15:46.117Z
Reserved: 2022-01-27T00:00:00.000Z
Link: CVE-2022-24086
Updated: 2024-08-03T03:59:23.565Z
Status : Analyzed
Published: 2022-02-16T17:15:13.307
Modified: 2025-10-23T14:51:16.013
Link: CVE-2022-24086
No data.