Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by a XML Injection (aka Blind XPath Injection) vulnerability that could lead in minor arbitrary file system read. Exploitation of this issue does not require user interaction.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-38207.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.4.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.4-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.4-p1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.4-p2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.4-p3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.4-p4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.5-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.5-p1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.5-p2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.5-p3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.6-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.6-p1"
}
]
}
]