PT-2022-1535 · Adobe · Commerce

CVE-2022-24086

·

Published

2022-02-13

·

Updated

2026-08-25

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Commerce versions prior to 2.4.3-p1 Adobe Commerce versions prior to 2.3.7-p2 Magento Open Source (affected versions not specified)
Description An improper input validation flaw exists during the checkout process, which can be exploited to achieve arbitrary code execution without requiring user interaction. This issue is a server-side template injection, where malicious template code is injected into input fields. Approximately 170,000 online stores worldwide are potentially affected. Real-world exploitation has involved creating customer accounts with malicious code in the first and last name fields or within the VAT field of an order. These attacks have been used to deploy remote access trojans (RATs), create PHP backdoors such as health check.php, or replace the generated/code/Magento/Framework/App/FrontController/Interceptor.php file with a malicious version.
Recommendations Update Adobe Commerce to version 2.4.3-p2 or later. Update Adobe Commerce to version 2.3.7-p3 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability for Magento Open Source.

Exploit

Fix

RCE

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00739
BIT-MAGENTO-2022-24086
CVE-2022-24086
GHSA-F8FV-F786-9933

Affected Products

Commerce