CRITICAL9.8
GHSA-f8fv-f786-9933
Magento improper input validation vulnerability
Quick fix
GHSA-f8fv-f786-9933 — magento/community-edition: upgrade to the fixed version with the command below.
composer require magento/community-edition:^2.3.7-p3Details
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/magento/community-edition
Introduced in:
2.3.3-p1Fixed in: 2.3.7-p3Fix
composer require magento/community-edition:^2.3.7-p3Packagist/magento/community-edition
Introduced in:
2.4.0Fixed in: 2.4.3-p2Fix
composer require magento/community-edition:^2.4.3-p2