← back
CVE-2021-36030highCWE-20

Magento Commerce Improper Input Validation During Checkout Process Could Lead To Privilege Escalation

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 2.3%
exploitation probability
2.3%top 18% of all CVEs
observed exploitation
nono source reports it
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability during the checkout process. An unauthenticated attacker can leverage this vulnerability to alter the price of items.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products
Adobe · Magento Commerce