CVE-2021-36038

Severity
6.5MEDIUM
EPSS
1.5%
top 19.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 1
Latest updateMay 24

Description

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability in the Multishipping Module. An authenticated attacker could leverage this vulnerability to achieve sensitive information disclosure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5adobe/magento_commerceunspecified2.4.2+3
Packagistmagento/community-edition2.4.2-p12.4.2-p2+1
NVDadobe/adobe_commerce2.3.02.3.7+2
NVDadobe/magento_open_source2.3.02.3.7+2

Patches

🔴Vulnerability Details

3
OSV
Magento discloses sensitive information via the Multishipping Module2022-05-24
GHSA
Magento discloses sensitive information via the Multishipping Module2022-05-24
CVEList
Magento Commerce Multishipping Module Improper Input Validation Could Lead To Information Exposure2021-09-01
CVE-2021-36038 (MEDIUM CVSS 6.5) | Magento Commerce versions 2.4.2 (an | cvebase.io