Adobe Commerce B2b 1.5.2

CPE Details

Adobe Commerce B2b 1.5.2
1.5.2
2025-05-19
09h41 +00:00
2025-05-19
09h41 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:adobe:commerce_b2b:1.5.2:-:*:*:*:*:*:*

Informations

Vendor

adobe

Product

commerce_b2b

Version

1.5.2

Update

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-43586 2025-06-10 16h08 +00:00 Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized elevated access. Exploitation of this issue does not require user interaction.
8.1
High
CVE-2025-47110 2025-06-10 16h08 +00:00 Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
9.1
Critical
CVE-2025-43585 2025-06-10 16h08 +00:00 Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access leading to a limited impact to confidentiality and a high impact to integrity. Exploitation of this issue does not require user interaction.
8.2
High