Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
https://www.edgescan.com/wp-content/uploads/2024/03/2023-Vulnerability-Statistics-Report.pdf
https://www.tenable.com/cyber-exposure/tenable-2022-threat-landscape-report
https://github.com/wubinworks/magento2-session-reaper-patch
https://github.com/wubinworks/magento2-template-filter-patch
https://github.com/iitsmel/Research
https://github.com/TomArni680/CVE-2022-24086-MASS-RCE
https://github.com/oK0mo/CVE-2022-24086-RCE-PoC
https://github.com/TomArni680/CVE-2022-24086-rce
https://github.com/TomArni680/CVE-2022-24086-poc
https://github.com/TomArni680/CVE-2022-24086-RCE
https://github.com/Sam00rx/CVE-2022-24087
https://github.com/shakeman8/CVE-2022-24086-RCE
https://github.com/advisories/GHSA-f8fv-f786-9933
https://helpx.adobe.com/security/products/magento/apsb22-12.html