Skip to content
CVSS 9.1 · CRITICAL

CVE-2025-54236

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.

Ver en NVD

Severidad

Puntaje: 9.1(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: NONE
Tipo de falla (CWE): CWE-20

EPSS

Probabilidad de explotación (próx. 30 días): 0.6482 (64.8%)
Percentil: 98.5%
EPSS: 2026-05-06

Afecta

adobe:commerceadobe:commerce_b2badobe:magento

Descripción técnica

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.

Publicada: 9/9/2025, 14:15:46
Última modificación: 5/5/2026, 1:00:01

Referencias

InicioEventosBlogRecursosEquipo