漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Adobe Commerce post-auth improper input validation leads to remote code execution
Vulnerability Description
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
输入验证不恰当
Vulnerability Title
Adobe Magento Commerce 输入验证错误漏洞
Vulnerability Description
Adobe Commerce是美国奥多比(Adobe)公司的一种面向商家和品牌的全球领先的数字商务解决方案。 Adobe Commerce(以前称为Magento Commerce) 和 Magento Open Source 存在输入验证错误漏洞,该漏洞源于对用户提供的输入的验证不充分。远程特权用户可以在系统上执行任意PHP代码。该漏洞允许远程用户在系统上执行任意代码。以下产品和版本受到影响:Adobe Commerce(以前称为Magento Commerce):2.4.0 - 2.4.3-p1_v1
CVSS Information
N/A
Vulnerability Type
N/A