Vulnerability record · CVE-2022-34258 · published 16 August 2022
CVE-2022-34258: Adobe Commerce stored XSS in admin form fields
Adobe · Commerce
Adobe Commerce versions 2.4.3-p2 and earlier, 2.3.7-p3 and earlier, and 2.4.4 and earlier contain a stored cross-site scripting flaw in vulnerable form fields. An attacker with admin privileges can inject malicious JavaScript that executes in a victim's browser when the victim views the affected page. Because the payload is stored, it can affect other users who later browse the page.
Description
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker with admin privileges to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityRequires admin privileges and user interaction, limiting exposure, but the stored XSS nature and high EPSS score warrant timely patching.
What it is
Adobe Commerce versions 2.4.3-p2 and earlier, 2.3.7-p3 and earlier, and 2.4.4 and earlier contain a stored cross-site scripting flaw in vulnerable form fields. An attacker with admin privileges can inject malicious JavaScript that executes in a victim's browser when the victim views the affected page. Because the payload is stored, it can affect other users who later browse the page.
Impact
An attacker with admin privileges can run arbitrary JavaScript in a victim's browser session, enabling session or data theft and actions performed as the victim. The CVSS vector limits scope to low confidentiality and integrity impact with no availability impact.
Attack surface
The flaw is network-reachable and requires high privileges (admin) to inject the payload, plus user interaction for a victim to browse the page containing the vulnerable field. No unauthenticated or pre-auth path is described.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware usage is documented in the record. EPSS is high (0.68515, 99.3rd percentile), indicating elevated predicted exploitation likelihood despite the absence of confirmed in-the-wild activity.
What to do
- Apply the Adobe Commerce security update referenced in Adobe advisory APSB22-38 (upgrade to a fixed release).
- Restrict and audit admin accounts; enforce least privilege and remove unused admin users.
- Enable CSP and output encoding controls to reduce XSS execution impact.
- Monitor and validate admin-submitted form content for script injection.
- Review logs for suspicious admin activity and unexpected script content in stored fields.
Detection
- Search application and web logs for admin form submissions containing script tags or JavaScript event handlers.
- Monitor for anomalous admin account activity, especially content edits followed by other users viewing the same pages.
- Inspect stored form field values for encoded or obfuscated JavaScript payloads.
- Alert on browser-side indicators such as unexpected outbound requests or cookie access from Commerce admin pages.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/magento/apsb22-38.html | Vendor Advisory |
| https://helpx.adobe.com/security/products/magento/apsb22-38.html | Vendor Advisory |
Track CVE-2022-34258 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-34258), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.