6.5

CVE-2021-36012

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a business logic error in the placeOrder graphql mutation. An authenticated attacker can leverage this vulnerability to altar the price of an item.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AdobeAdobe Commerce Version >= 2.3.0 <= 2.3.7
AdobeAdobe Commerce Version >= 2.4.0 <= 2.4.2
AdobeAdobe Commerce Version2.4.2 Updatep1
AdobeMagento Open Source Version >= 2.3.0 <= 2.3.7
AdobeMagento Open Source Version >= 2.4.0 <= 2.4.2
AdobeMagento Open Source Version2.4.2 Updatep1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.79% 0.726
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
psirt@adobe.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N