CVE-2025-24408

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation. A low-privileged attacker could gain unauthorized access to sensitive information. Exploitation of this issue does not require user interaction.
Configurations

No configuration.

History

27 Feb 2025, 21:15

Type Values Removed Values Added
Summary
  • (es) Las versiones 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 y anteriores de Adobe Commerce se ven afectadas por una vulnerabilidad de exposición de información que podría provocar una escalada de privilegios. Un atacante con pocos privilegios podría obtener acceso no autorizado a información confidencial. La explotación de este problema no requiere la interacción del usuario.
Summary (en) Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation. A low-privileged attacker could gain unauthorized access to sensitive information. Exploitation of this issue does not require user interaction. (en) Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation. A low-privileged attacker could gain unauthorized access to sensitive information. Exploitation of this issue does not require user interaction.

11 Feb 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 18:15

Updated : 2025-02-27 21:15


NVD link : CVE-2025-24408

Mitre link : CVE-2025-24408

CVE.ORG link : CVE-2025-24408


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor