Adobe Magento是美国奥多比(Adobe)公司的一套开源的PHP电子商务系统。该系统提供权限管理、搜索引擎和支付网关等功能。 Adobe Magento 存在信息泄露漏洞。该漏洞是由于应用程序输出了过多的数据。通过身份验证的远程管理员可以获得对敏感信息的未经授权的访问,例如web应用程序的完整安装路径。受影响的产品及版本如下:Magento Open Source: 2.3.0, 2.3.1, 2.3.2, 2.3.2-p2, 2.3.3, 2.3.3-p1, 2.3.4, 2.3.4-p2,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Adobe | Magento Commerce | unspecified ~ 2.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-28580 | 8.8 HIGH | Medium by Adobe file parsing buffer overflow vulnerability could lead to arbitrary code ex |
| CVE-2021-21104 | 8.8 HIGH | Adobe Illustrator memory corruption vulnerability could lead to remote code execution |
| CVE-2021-21105 | 8.8 HIGH | Adobe Illustrator memory corruption vulnerability could lead to remote code execution |
| CVE-2021-28571 | 8.3 HIGH | Adobe After Effects improper neutralization of special elements could lead to remote code |
| CVE-2021-28568 | 5.8 MEDIUM | Adobe Genuine Services insecure file permission could lead to privilege escalation |
| CVE-2021-21103 | 4.3 MEDIUM | Adobe Illustrator memory corruption vulnerability could lead to information disclosure |
| CVE-2021-28569 | 4.3 MEDIUM | Adobe Media Encoder VOB file parsing out-of-bounds read could lead to information disclosu |
| CVE-2021-28581 | Adobe Creative Cloud Desktop uncontrolled search path element vulnerability could lead to | |
| CVE-2021-28567 | Magento Commerce improper authorization allows an authenticated user to perform certain fu |
No comments yet