Vulnerability Details CVE-2024-34110
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. A high-privilege attacker could exploit this vulnerability by uploading a malicious file to the system, which could then be executed. Exploitation of this issue does not require user interaction.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.03
EPSS Ranking 85.9%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2024-34110
-
cpe:2.3:a:adobe:commerce:2.3.7
-
cpe:2.3:a:adobe:commerce:2.4.0
-
cpe:2.3:a:adobe:commerce:2.4.1
-
cpe:2.3:a:adobe:commerce:2.4.2
-
cpe:2.3:a:adobe:commerce:2.4.3
-
cpe:2.3:a:adobe:commerce:2.4.4
-
cpe:2.3:a:adobe:commerce:2.4.5
-
cpe:2.3:a:adobe:commerce:2.4.6
-
cpe:2.3:a:adobe:commerce_webhooks:1.2.0
-
cpe:2.3:a:adobe:commerce_webhooks:1.2.1
-
cpe:2.3:a:adobe:commerce_webhooks:1.3.0
-
cpe:2.3:a:adobe:commerce_webhooks:1.3.1
-
cpe:2.3:a:adobe:commerce_webhooks:1.4.0
-
cpe:2.3:a:adobe:magento:2.4.4
-
cpe:2.3:a:adobe:magento:2.4.5
-
cpe:2.3:a:adobe:magento:2.4.6
-
cpe:2.3:a:adobe:magento:2.4.7