CVE-2022-24086
KEVHIGH 10.0EPSS 99.2%
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 99.20% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-02-15
- Nuclei
- critical · CWE-20
- Published
- 2022-02-16
- Updated
- 2025-10-21
Proof-of-concept exploits (9)
- BurpRoot/CVE-2022-240860★ · 2023-09-03
- Mr-xn/CVE-2022-2408635★ · 2022-12-16
- NHPT/CVE-2022-24086-RCE0★ · 2022-03-15
- akr3ch/CVE-2022-240862★ · 2022-10-01
- nanaao/CVE-2022-24086-RCE0★ · 2022-02-26
- oK0mo/CVE-2022-24086-RCE-PoC6★ · 2022-08-06
- pescepilota/CVE-2022-240866★ · 2022-12-20
- rxerium/CVE-2022-240861★ · 2025-10-14
- seymanurmutlu/CVE-2022-24086-CVE-2022-240872★ · 2022-06-12