ZeroHour
Sansec (Magento / e-commerce security)published ()ingested Sansec Forensics Team

Magento Security Release APSB25

criticalVulnerabilityimportance 60CVE-2023-38218

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-38218
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Incorrect Author

Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Incorrect Authorization . An authenticated attacker can exploit this to achieve information exposure and privilege escalation.

NVD description · AI analysis pending
8.8<1%
  • adobe commerce
  • adobe magento
Full article335 words · extracted from sansec.io · click to collapse

Sansec

written by a human

Critical (CVSS 9.4) release enables attackers to take control of customer accounts.

Magento Security Release APSB25-08 [Impact Analysis]

APSB25-08 released on Feb 11th, 2025

Critical Adobe Commerce/Magento security patches have just been released (CVSS 9.4/10)

New versions: 2.4.4-p12, 2.4.5-p11, 2.4.6-p9, 2.4.7-p4, additionally 2.4.8-beta2. You should schedule an upgrade ASAP.

  • Request validation was added to the Asynchronous Web API. This is a port of CVE-2023-38218, which previously received an 8.8 CVSS score (see our analysis) but is now a critical 9.4. Unauthorized attackers can take control of customer accounts. There is an isolated patch available if you cannot upgrade.
  • Several stored XSS that could be exploited with admin access. Areas affected are system configuration, product edit page, customer edit page, and the dashboard.
  • A locking mechanism was added to prevent coupons from being used more than their allowed limit.
  • In the wake of CosmicSting, a new "extensible data re-encryption mechanism" was added to make changing your encryption key less painful. Despite Adobes claim that it is in 2.4.8-beta only, it is present in the 2.4.4 patch as well.
  • A directory traversal issue was fixed that would allow admins to download arbitrary files within the var folder.
  • TinyMCE was downgraded from version 7 to version 6 due to compatibility issues with OSL (thanks Fabrizio Balliano and Tu Van)

eComscan will alert you about vulnerable installations.

Read more

Protect your store now!

Block all known Magento attacks, while you schedule the latest critical patch until a convenient moment. No more downtime and instability from rushed patching.

Get Sansec Shield

Scan your store now
for malware & vulnerabilities

$ curl ecomscan.com | sh

copy code

eComscan is the most thorough security scanner for Magento, Adobe Commerce, Shopware, WooCommerce, Sylius and many more.

Learn more

Text extracted automatically; images, tables and formatting may be missing. Original: https://sansec.io/research/magento-apsb25-08