Published Oct 8, 2024.
Improper authentication (CVE-2024-45115) that allows privilege escalation without prior authentication. Part of the October 2024 patch set that followed the CosmicSting exploitation wave.
| CVE | CVSS | Type | Impact | Auth required |
|---|---|---|---|---|
| CVE-2024-45115 | 9.8 | improper-authentication | privilege-escalation | no |
Get this bulletin as JSON:
curl -s https://magento.watch/api/v1/security-bulletins/APSB24-73
magento.watch is built and maintained by Łukasz Bajsarowicz, solo, on weekends. If it has saved you a few hours, consider chipping in.
Sponsor →Łukasz takes on Magento 2 and Adobe Commerce engagements — upgrades, audits, performance, team mentoring.
Get in touch →