Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-24086— Adobe Commerce checkout improper input validation leads to remote code execution

CVSS 9.8 · Critical KEV EPSS 93.74% · P100
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-24086

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Adobe Commerce checkout improper input validation leads to remote code execution
Source: NVD (National Vulnerability Database)
Vulnerability Description
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
输入验证不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Adobe Magento 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Adobe Magento是美国奥多比(Adobe)公司的一套开源的PHP电子商务系统。该系统提供权限管理、搜索引擎和支付网关等功能。 Adobe Magento 存在输入验证错误漏洞,该漏洞源于输入验证不当。攻击者可利用该漏洞向应用程序发送专门设计的请求,并在目标系统上执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
AdobeMagento Commerce unspecified ~ 2.4.3-p1 -

II. Public POCs for CVE-2022-24086

#POC DescriptionSource LinkShenlong Link
1CVE-2022-24086 about Magento RCE https://github.com/Mr-xn/CVE-2022-24086POC Details
2CVE-2022-24086 RCEhttps://github.com/nanaao/CVE-2022-24086-RCEPOC Details
3Nonehttps://github.com/NHPT/CVE-2022-24086-RCEPOC Details
4Verifed Proof of Concept on CVE-2022-24086https://github.com/oK0mo/CVE-2022-24086-RCE-PoCPOC Details
5Nonehttps://github.com/seymanurmutlu/CVE-2022-24086-CVE-2022-24087POC Details
6PoC of CVE-2022-24086https://github.com/akr3ch/CVE-2022-24086POC Details
7Proof of concept of CVE-2022-24086https://github.com/pescepilota/CVE-2022-24086POC Details
8CVE-2022-24086 POC examplehttps://github.com/BurpRoot/CVE-2022-24086POC Details
9An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.https://github.com/rxerium/CVE-2022-24086POC Details
10Magento 2 patch for CVE-2022-24086. Fix the RCE vulnerability and related bugs by performing deep template variable escaping. If you cannot upgrade Magento or cannot apply the official patches, try this one.https://github.com/wubinworks/magento2-template-filter-patchPOC Details
11Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-24086.yamlPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-24086

登录查看更多情报信息。

Same Patch Batch · Adobe · 2022-02-16 · 18 CVEs total

CVE-2022-231887.8 HIGHAdobe Illustrator Buffer Overflow could lead to Arbitrary code execution
CVE-2022-231867.8 HIGHAdobe Illustrator Out-of-bounds Write could lead to Arbitrary code execution
CVE-2022-232037.8 HIGHAdobe Photoshop Buffer Overflow could lead to Arbitrary code execution
CVE-2022-232027.0 HIGHAdobe Creative Cloud Desktop Uncontrolled Search Path Element Arbitrary code execution
CVE-2022-231955.5 MEDIUMAdobe Illustrator Out-of-bounds Read could lead to Memory leak
CVE-2022-232045.5 MEDIUMAdobe Premiere Rush JPEG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerabil
CVE-2022-231975.5 MEDIUMAdobe Illustrator Out-of-bounds Read could lead to Memory leak
CVE-2022-231995.5 MEDIUMAdobe Illustrator NULL Pointer Dereference Application denial-of-service
CVE-2022-231985.5 MEDIUMAdobe Illustrator NULL Pointer Dereference Application denial-of-service
CVE-2022-231965.5 MEDIUMAdobe Illustrator Out-of-bounds Read could lead to Memory leak
CVE-2022-231925.5 MEDIUMAdobe Illustrator Out-of-bounds Read could lead to Memory leak
CVE-2022-231945.5 MEDIUMAdobe Illustrator Out-of-bounds Read could lead to Memory leak
CVE-2022-231915.5 MEDIUMAdobe Illustrator Out-of-bounds Read could lead to Memory leak
CVE-2022-231905.5 MEDIUMAdobe Illustrator Out-of-bounds Read could lead to Memory leak
CVE-2022-231895.5 MEDIUMAdobe Illustrator NULL Pointer Dereference Application denial-of-service
CVE-2022-231935.5 MEDIUMAdobe Illustrator Out-of-bounds Read could lead to Memory leak
CVE-2022-23200Adobe After Effects 3GP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabili

IV. Related Vulnerabilities

V. Comments for CVE-2022-24086

No comments yet


Leave a comment