CVE-2021-28563
Magento Commerce improper Authorization via the 'Create Customer' endpoint
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper Authorization vulnerability via the 'Create Customer' endpoint. Successful exploitation could lead to unauthorized modification of customer data by an unauthenticated attacker. Access to the admin console is required for successful exploitation.
Magento versiones 2.4.2 (y anteriores), versiones 2.4.1-p1 (y anteriores) y versiones 2.3.6-p1 (y anteriores), están afectadas por una vulnerabilidad de Autorización Inapropiada por medio del endpoint "Create Customer". Una explotación con éxito podría conllevar a una modificación no autorizada de los datos del cliente por parte de un atacante no autenticado. Es requerido acceso a la consola de administración para una explotación con éxito
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-03-16 CVE Reserved
- 2021-06-28 CVE Published
- 2024-02-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-285: Improper Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/magento/apsb21-30.html | 2022-08-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | < 2.3.7 Search vendor "Magento" for product "Magento" and version " < 2.3.7" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | < 2.3.7 Search vendor "Magento" for product "Magento" and version " < 2.3.7" | open_source |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | >= 2.4.0 <= 2.4.2 Search vendor "Magento" for product "Magento" and version " >= 2.4.0 <= 2.4.2" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | >= 2.4.0 <= 2.4.2 Search vendor "Magento" for product "Magento" and version " >= 2.4.0 <= 2.4.2" | open_source |
Affected
|