Loading HuntDB...

GHSA-873m-72g6-853g

GitHub Security Advisory

Magento Open Source Cross-Site Scripting (XSS) vulnerability

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Magento Open Source versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code. If an admin attacker can trick a user into clicking a specially crafted link or submitting a form, malicious scripts may be executed within the context of the victim's browser and have high impact on confidentiality and integrity. Exploitation of this issue requires user interaction.

Affected Packages

Packagist magento/community-edition
Affected versions: 2.4.7-beta1 (fixed in 2.4.7-p3)
Packagist magento/community-edition
Affected versions: 2.4.6-p1 (fixed in 2.4.6-p8)
Packagist magento/community-edition
Affected versions: 2.4.5-p1 (fixed in 2.4.5-p10)
Packagist magento/community-edition
Affected versions: 0 (fixed in 2.4.4-p11)
Packagist magento/community-edition
Packagist magento/community-edition
Packagist magento/community-edition
Packagist magento/community-edition

Related CVEs

Key Information

GHSA ID
GHSA-873m-72g6-853g
Published
October 10, 2024 12:31 PM
Last Modified
October 11, 2024 7:12 PM
CVSS Score
5.0 /10
Primary Ecosystem
Packagist
Primary Package
magento/community-edition
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 1, 2025 6:44 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.