CVE-2025-49557 | Adobe Commerce up to 2.4.9-alpha1 form cross site scripting (apsb25-71)
A vulnerability was found in Adobe Commerce up to 2.4.9-alpha1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument form leads to cross site scripting.
This vulnerability is known as CVE-2025-49557. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.