Lucene search

K
osvGoogleOSV:CVE-2021-39864
HistoryOct 15, 2021 - 3:15 p.m.

CVE-2021-39864

2021-10-1515:15:08
Google
osv.dev
7
adobe commerce
csrf vulnerability
wishlist share link
unauthorized addition
customer cart
unauthenticated attacker
admin console.

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

29.5%

Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to customer cart by an unauthenticated attacker. Access to the admin console is not required for successful exploitation.

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

29.5%

Related for OSV:CVE-2021-39864