Lucene search

K
githubGitHub Advisory DatabaseGHSA-39CH-RG26-GMQ5
HistoryMay 24, 2022 - 7:06 p.m.

Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies

2022-05-2419:06:25
CWE-79
GitHub Advisory Database
github.com
6
magento
cross-site scripting
dom-based
vulnerability
cookies
javascript
unauthenticated attacker
user interaction
exploitation
software

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

6.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N

AI Score

6.3

Confidence

High

EPSS

0.002

Percentile

56.2%

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mage-messages cookies. Successful exploitation could lead to arbitrary JavaScript execution by an unauthenticated attacker. User interaction is required for successful exploitation.

Affected configurations

Vulners
Node
magentocommunity-editionRange<2.3.7
OR
magentocommunity-editionRange2.4.02.4.2-p1
VendorProductVersionCPE
magentocommunity-edition*cpe:2.3:a:magento:community-edition:*:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

6.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N

AI Score

6.3

Confidence

High

EPSS

0.002

Percentile

56.2%

Related for GHSA-39CH-RG26-GMQ5