← back
CVE-2021-36032highCWE-20

Magento Commerce Improper Input Validation Could Lead To Information Exposure and Privilege Escalation

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.3epss 2.2%
exploitation probability
2.2%top 18% of all CVEs
observed exploitation
nono source reports it
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An authenticated attacker can trigger an insecure direct object reference in the `V1/customers/me` endpoint to achieve information exposure and privilege escalation.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Affected products
Adobe · Magento Commerce