CVE-2021-21019
- EPSS 3.01%
- Veröffentlicht 11.02.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:47:24
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the Widgets module. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the adm...
CVE-2021-21020
- EPSS 0.13%
- Veröffentlicht 11.02.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:47:24
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an access control bypass vulnerability in the Login as Customer module. Successful exploitation could lead to unauthorized access to restricted res...
CVE-2021-21022
- EPSS 0.15%
- Veröffentlicht 11.02.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:47:25
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object reference (IDOR) in the product module. Successful exploitation could lead to unauthorized access to restricted resources...
CVE-2021-21023
- EPSS 2.82%
- Veröffentlicht 11.02.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:47:25
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting vulnerability in the admin console. Successful exploitation could lead to arbitrary JavaScript execution in the victi...
CVE-2021-21024
- EPSS 2.07%
- Veröffentlicht 11.02.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:47:25
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a blind SQL injection vulnerability in the Search module. Successful exploitation could lead to unauthorized access to restricted resources by an una...
CVE-2021-21025
- EPSS 4.72%
- Veröffentlicht 11.02.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:47:25
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the product layout updates. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to...
- EPSS 0.68%
- Veröffentlicht 11.02.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:47:25
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by an improper authorization vulnerability in the integrations module. Successful exploitation could lead to unauthorized access to restricted resources...
CVE-2021-21027
- EPSS 0.15%
- Veröffentlicht 11.02.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:47:25
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via the GraphQL API. Successful exploitation could lead to unauthorized modification of customer me...
CVE-2021-21029
- EPSS 43.5%
- Veröffentlicht 11.02.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:47:25
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter. Successful exploitation could lead to arbitrary JavaScript execution in the vict...
CVE-2021-21030
- EPSS 6.28%
- Veröffentlicht 11.02.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:47:26
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting (XSS) in the customer address upload feature. Successful exploitation could lead to arbitrary JavaScript execution in...