Lucene search

K
cveAdobeCVE-2021-39864
HistoryOct 15, 2021 - 3:15 p.m.

CVE-2021-39864

2021-10-1515:15:08
CWE-352
adobe
web.nvd.nist.gov
35
cve-2021-39864
adobe commerce
csrf
vulnerability
wishlist share link

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

29.5%

Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to customer cart by an unauthenticated attacker. Access to the admin console is not required for successful exploitation.

Affected configurations

Nvd
Vulners
Node
adobecommerceRange2.3.7
OR
adobecommerceMatch2.3.7p1
OR
adobecommerceMatch2.4.2
OR
adobecommerceMatch2.4.2p1
OR
adobecommerceMatch2.4.2p2
OR
adobecommerceMatch2.4.3
Node
adobemagento_open_sourceRange2.3.7
OR
adobemagento_open_sourceMatch2.3.7p1
OR
adobemagento_open_sourceMatch2.4.2
OR
adobemagento_open_sourceMatch2.4.2p1
OR
adobemagento_open_sourceMatch2.4.2p2
OR
adobemagento_open_sourceMatch2.4.3
VendorProductVersionCPE
adobecommerce*cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:*
adobecommerce2.3.7cpe:2.3:a:adobe:commerce:2.3.7:p1:*:*:*:*:*:*
adobecommerce2.4.2cpe:2.3:a:adobe:commerce:2.4.2:*:*:*:*:*:*:*
adobecommerce2.4.2cpe:2.3:a:adobe:commerce:2.4.2:p1:*:*:*:*:*:*
adobecommerce2.4.2cpe:2.3:a:adobe:commerce:2.4.2:p2:*:*:*:*:*:*
adobecommerce2.4.3cpe:2.3:a:adobe:commerce:2.4.3:*:*:*:*:*:*:*
adobemagento_open_source*cpe:2.3:a:adobe:magento_open_source:*:*:*:*:*:*:*:*
adobemagento_open_source2.3.7cpe:2.3:a:adobe:magento_open_source:2.3.7:p1:*:*:*:*:*:*
adobemagento_open_source2.4.2cpe:2.3:a:adobe:magento_open_source:2.4.2:*:*:*:*:*:*:*
adobemagento_open_source2.4.2cpe:2.3:a:adobe:magento_open_source:2.4.2:p1:*:*:*:*:*:*
Rows per page:
1-10 of 121

CNA Affected

[
  {
    "product": "Magento Commerce",
    "vendor": "Adobe",
    "versions": [
      {
        "lessThanOrEqual": "2.4.3",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "2.4.2-p2",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "2.3.7-p1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "None",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

29.5%

Related for CVE-2021-39864