CVE-2021-21030Cross-site Scripting in Magento

Severity
8.1HIGHNVD
EPSS
8.3%
top 7.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 11
Latest updateMay 24

Description

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting (XSS) in the customer address upload feature. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Exploitation of this issue requires user interaction.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages4 packages

NVDmagento/magento< 2.3.6+3
Packagistmagento/community-edition2.4.02.4.1-p1+1
CVEListV5adobe/magento_commerceunspecified2.4.1+3

🔴Vulnerability Details

3
OSV
Magento stored cross-site scripting (XSS) in the customer address upload feature2022-05-24
GHSA
Magento stored cross-site scripting (XSS) in the customer address upload feature2022-05-24
CVEList
Magento Commerce Stored Cross-site Scripting Could Lead To Arbitrary Javascript Execution2021-02-11