PT-2022-1535 · Adobe · Commerce
CVE-2022-24086
·
Published
2022-02-13
·
Updated
2026-08-25
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Commerce versions prior to 2.4.3-p1
Adobe Commerce versions prior to 2.3.7-p2
Magento Open Source (affected versions not specified)
Description
An improper input validation flaw exists during the checkout process, which can be exploited to achieve arbitrary code execution without requiring user interaction. This issue is a server-side template injection, where malicious template code is injected into input fields. Approximately 170,000 online stores worldwide are potentially affected. Real-world exploitation has involved creating customer accounts with malicious code in the first and last name fields or within the VAT field of an order. These attacks have been used to deploy remote access trojans (RATs), create PHP backdoors such as
health check.php, or replace the generated/code/Magento/Framework/App/FrontController/Interceptor.php file with a malicious version.Recommendations
Update Adobe Commerce to version 2.4.3-p2 or later.
Update Adobe Commerce to version 2.3.7-p3 or later.
At the moment, there is no information about a newer version that contains a fix for this vulnerability for Magento Open Source.
Exploit
Fix
RCE
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Commerce