Lucene search

K
osvGoogleOSV:GHSA-39CH-RG26-GMQ5
HistoryMay 24, 2022 - 7:06 p.m.

Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies

2022-05-2419:06:25
Google
osv.dev
2
magento
cross-site scripting
dom-based
cookies
vulnerability
version 2.4.2
version 2.4.1-p1
version 2.3.6-p1
unauthenticated attacker
user interaction

AI Score

6.2

Confidence

High

EPSS

0.002

Percentile

56.2%

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mage-messages cookies. Successful exploitation could lead to arbitrary JavaScript execution by an unauthenticated attacker. User interaction is required for successful exploitation.

AI Score

6.2

Confidence

High

EPSS

0.002

Percentile

56.2%

Related for OSV:GHSA-39CH-RG26-GMQ5