← volver
CVE-2021-36032highCWE-20

Magento Commerce Improper Input Validation Could Lead To Information Exposure and Privilege Escalation

21Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 8.3epss 2.2%
probabilidad de explotación
2.2%top 18% de las CVE
explotación observada
noninguna fuente lo reporta
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An authenticated attacker can trigger an insecure direct object reference in the `V1/customers/me` endpoint to achieve information exposure and privilege escalation.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Productos afectados
Adobe · Magento Commerce