CVE-2021-21029
Magento Commerce Reflected Cross-site Scripting Vulnerability Could Lead To Arbitrary JavaScript Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Access to the admin console is required for successful exploitation.
Magento versiones 2.4.1 (y anteriores), versiones 2.4.0-p1 (y anteriores) y versiones 2.3.6 (y anteriores), están afectadas por una vulnerabilidad de tipo Cross-site Scripting Reflejado por medio del parámetro "file". Una explotación con éxito podría conllevar a una ejecución arbitraria de JavaScript en el navegador de la víctima. Es requerido un acceso a la consola de administración para una explotación con éxito
Adobe Magento Commerce versions prior to 2.4.2 suffer from a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-18 CVE Reserved
- 2021-02-10 CVE Published
- 2023-03-07 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/magento/apsb21-08.html | 2022-01-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | < 2.3.6 Search vendor "Magento" for product "Magento" and version " < 2.3.6" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | < 2.3.6 Search vendor "Magento" for product "Magento" and version " < 2.3.6" | open_source |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.3.6 Search vendor "Magento" for product "Magento" and version "2.3.6" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.3.6 Search vendor "Magento" for product "Magento" and version "2.3.6" | open_source |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.0 Search vendor "Magento" for product "Magento" and version "2.4.0" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.0 Search vendor "Magento" for product "Magento" and version "2.4.0" | open_source |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.0 Search vendor "Magento" for product "Magento" and version "2.4.0" | p1, commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.0 Search vendor "Magento" for product "Magento" and version "2.4.0" | p1, open_source |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.1 Search vendor "Magento" for product "Magento" and version "2.4.1" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.1 Search vendor "Magento" for product "Magento" and version "2.4.1" | open_source |
Affected
|