Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation. A low-privileged attacker could gain unauthorized access to sensitive information. Exploitation of this issue does not require user interaction.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Feb 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Feb 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation. A low-privileged attacker could gain unauthorized access to sensitive information. Exploitation of this issue does not require user interaction. | |
Title | Adobe Commerce | Information Exposure (CWE-200) | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2025-02-11T18:57:56.909Z
Reserved: 2025-01-21T17:00:45.700Z
Link: CVE-2025-24408

Updated: 2025-02-11T18:49:14.597Z

Status : Received
Published: 2025-02-11T18:15:41.677
Modified: 2025-02-11T18:15:41.677
Link: CVE-2025-24408

No data.