CVE-2024-39410
CVSS V2 None
CVSS V3 None
Description
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor unauthorised actions on behalf of a user. The vulnerability could be exploited by tricking a victim into clicking a link or loading a page that submits a malicious request. Exploitation of this issue requires user interaction.
Overview
- CVE ID
- CVE-2024-39410
- Assigner
- adobe
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-08-14T11:57:17.152Z
- Last Modified Date
- 2024-08-14T14:13:31.509Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://helpx.adobe.com/security/products/magento/apsb24-61.html | vendor-advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-39410 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39410 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-08-15 13:17:05 | Added to TrackCVE |