Miggo Logo

CVE-2025-54263: Magento provides incorrect authorization through a security feature bypass

8.1

CVSS Score
3.1

Basic Information

EPSS Score
0.21514%
Published
10/14/2025
Updated
10/21/2025
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
magento/community-editioncomposer>= 2.4.9-alpha1, < 2.4.9-alpha32.4.9-alpha3
magento/community-editioncomposer>= 2.4.8-beta1, < 2.4.8-p32.4.8-p3
magento/community-editioncomposer>= 2.4.7-beta1, < 2.4.7-p82.4.7-p8
magento/community-editioncomposer< 2.4.6-p132.4.6-p13
magento/community-editioncomposer= 2.4.8
magento/community-editioncomposer= 2.4.7
magento/community-editioncomposer= 2.4.6
magento/project-community-editioncomposer<= 2.0.2

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

M***nto v*rsions *.*.*-*lp***, *.*.*-p*, *.*.*-p*, *.*.*-p**, *.*.*-p**, *.*.*-p** *n* **rli*r *r* *****t** *y *n In*orr**t *ut*oriz*tion vuln*r**ility. * low-privil**** *tt**k*r *oul* l*v*r*** t*is vuln*r**ility to *yp*ss s**urity m**sur*s *n* m*int

Reasoning

No *n*lysis *v*il**l*