CVE-2022-34253
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution. Exploitation of this issue does not require user interaction.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 37.19%
- CWE
- CWE-91
- Published
- 2022-08-16
- Last modified
- 2026-03-13
Affected products
- Adobe Magento Commerce
Weakness type
Related vulnerabilities
- CVE-2023-46214 — Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing
- CVE-2021-36020 — Magento Commerce XML Injection Vulnerability In The 'City' Field Could Lead To Remote Code Execution
- CVE-2021-36033 — Magento Commerce Widgets Module XML Injection Vulnerability Could Lead To Remote Code Execution
- CVE-2021-36028 — Magento Commerce XML Injection Vulnerability Could Lead To Remote Code Execution
- CVE-2020-8479 — ABB Central Licensing System - XML External Entity Injection
- CVE-2021-21025 — Magento Commerce XML Injection Could Lead To Arbitrary Code Execution
- CVE-2021-21019 — Magento Commerce XML Injection Could Lead To Remote Code Execution
- CVE-2021-39181 — Unsafe Deserialization of User Data Using XStream