CVE-2021-28556
published 2021-06-28CVE-2021-28556: Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on…
PriorityP420medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
1.40%
69.1th percentile
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mage-messages cookies. Successful exploitation could lead to arbitrary JavaScript execution by an unauthenticated attacker. User interaction is required for successful exploitation.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | magento_commerce | unspecified – 2.4.2 | — |
| magento | community-edition | >= 0 < 2.3.7 | 2.3.7 |
| magento | community-edition | >= 2.4.0 < 2.4.2-p1 | 2.4.2-p1 |
| magento | magento | < 2.3.7 | 2.3.7 |
| magento | magento | 2.4.0 – 2.4.2 | — |
| magento | project-community-edition | 0 – 2.0.2 | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies
ghsa·2022-05-24
CVE-2021-28556 [MEDIUM] CWE-79 Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies
Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mage-messages cookies. Successful exploitation could lead to arbitrary JavaScript execution by an unauthenticated attacker. User interaction is required for successful exploitation.
OSV
Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies
osv·2022-05-24
CVE-2021-28556 [MEDIUM] Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies
Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mage-messages cookies. Successful exploitation could lead to arbitrary JavaScript execution by an unauthenticated attacker. User interaction is required for successful exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-06-28
Published