CVE-2021-21024
Magento Commerce Blind SQL Injection Could Lead To Unauthorized Access
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a blind SQL injection vulnerability in the Search module. Successful exploitation could lead to unauthorized access to restricted resources by an unauthenticated attacker. Access to the admin console is required for successful exploitation.
Magento versiones 2.4.1 (y anteriores), versiones 2.4.0-p1 (y anteriores) y versiones 2.3.6 (y anteriores), están afectadas por una vulnerabilidad de inyección SQL ciega en el módulo Search. Una explotación con éxito podría conllevar a un acceso no autorizado a recursos restringidos por parte de un atacante no autenticado. Es requerido un acceso a la consola de administración para una explotación con éxito
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-18 CVE Reserved
- 2021-02-11 CVE Published
- 2023-11-08 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/magento/apsb21-08.html | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | < 2.3.6 Search vendor "Magento" for product "Magento" and version " < 2.3.6" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | < 2.3.6 Search vendor "Magento" for product "Magento" and version " < 2.3.6" | open_source |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.3.6 Search vendor "Magento" for product "Magento" and version "2.3.6" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.3.6 Search vendor "Magento" for product "Magento" and version "2.3.6" | open_source |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.0 Search vendor "Magento" for product "Magento" and version "2.4.0" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.0 Search vendor "Magento" for product "Magento" and version "2.4.0" | open_source |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.0 Search vendor "Magento" for product "Magento" and version "2.4.0" | p1, commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.0 Search vendor "Magento" for product "Magento" and version "2.4.0" | p1, open_source |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.1 Search vendor "Magento" for product "Magento" and version "2.4.1" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.1 Search vendor "Magento" for product "Magento" and version "2.4.1" | open_source |
Affected
|