Lucene search

K
nvd[email protected]NVD:CVE-2021-21023
HistoryFeb 11, 2021 - 8:15 p.m.

CVE-2021-21023

2021-02-1120:15:14
CWE-79
web.nvd.nist.gov
8
magento
xss
vulnerability
admin console
versions 2.4.1
2.4.0-p1
2.3.6

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS

0.005

Percentile

76.3%

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting vulnerability in the admin console. Successful exploitation could lead to arbitrary JavaScript execution in the victim’s browser. Access to the admin console is required for successful exploitation.

Affected configurations

Nvd
Node
magentomagentoRange<2.3.6commerce
OR
magentomagentoRange<2.3.6open_source
OR
magentomagentoMatch2.3.6-commerce
OR
magentomagentoMatch2.3.6-open_source
OR
magentomagentoMatch2.4.0-commerce
OR
magentomagentoMatch2.4.0-open_source
OR
magentomagentoMatch2.4.0p1commerce
OR
magentomagentoMatch2.4.0p1open_source
OR
magentomagentoMatch2.4.1-commerce
OR
magentomagentoMatch2.4.1-open_source
VendorProductVersionCPE
magentomagento*cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*
magentomagento*cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*
magentomagento2.3.6cpe:2.3:a:magento:magento:2.3.6:-:*:*:commerce:*:*:*
magentomagento2.3.6cpe:2.3:a:magento:magento:2.3.6:-:*:*:open_source:*:*:*
magentomagento2.4.0cpe:2.3:a:magento:magento:2.4.0:-:*:*:commerce:*:*:*
magentomagento2.4.0cpe:2.3:a:magento:magento:2.4.0:-:*:*:open_source:*:*:*
magentomagento2.4.0cpe:2.3:a:magento:magento:2.4.0:p1:*:*:commerce:*:*:*
magentomagento2.4.0cpe:2.3:a:magento:magento:2.4.0:p1:*:*:open_source:*:*:*
magentomagento2.4.1cpe:2.3:a:magento:magento:2.4.1:-:*:*:commerce:*:*:*
magentomagento2.4.1cpe:2.3:a:magento:magento:2.4.1:-:*:*:open_source:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS

0.005

Percentile

76.3%

Related for NVD:CVE-2021-21023