ZeroHour

CVE-2025-22384

CVSS 3.1
7.5 high
EPSS
<1%p35
Published
()
Modified
Description

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios where requests are altered before reaching the server.

Vendors
optimizely
Products
configured commerce
Weakness
CWE-472
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.