// For flags

CVE-2021-21427

Backport for CVE-2021-21024 Blind SQLi from Magento 2

Severity Score

7.2
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Magento-lts is a long-term support alternative to Magento Community Edition (CE). A vulnerability in magento-lts versions before 19.4.13 and 20.0.9 potentially allows an administrator unauthorized access to restricted resources. This is a backport of CVE-2021-21024. The vulnerability is patched in versions 19.4.13 and 20.0.9.

Magento-lts es una alternativa de soporte a largo plazo a Magento Community Edition (CE). Una vulnerabilidad en magento-lts versiones anteriores a 19.4.13 y 20.0.9, potencialmente permite a un administrador acceso no autorizado a recursos restringidos. Este es una puerta trasera de CVE-2021-21024. La vulnerabilidad está parcheada en versiones 19.4.13 y 20.0.9

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-12-22 CVE Reserved
  • 2021-04-21 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Openmage
Search vendor "Openmage"
Magento
Search vendor "Openmage" for product "Magento"
< 19.4.13
Search vendor "Openmage" for product "Magento" and version " < 19.4.13"
lts
Affected
Openmage
Search vendor "Openmage"
Magento
Search vendor "Openmage" for product "Magento"
>= 20.0.0 < 20.0.9
Search vendor "Openmage" for product "Magento" and version " >= 20.0.0 < 20.0.9"
lts
Affected