CVE-2021-28563

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper Authorization vulnerability via the 'Create Customer' endpoint. Successful exploitation could lead to unauthorized modification of customer data by an unauthenticated attacker. Access to the admin console is required for successful exploitation.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*
cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*
cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*
cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*

History

02 Aug 2022, 15:59

Type Values Removed Values Added
CWE CWE-285 NVD-CWE-Other

02 Jul 2021, 15:46

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 6.4
v3 : 6.5
CWE CWE-285
CPE cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*
cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*
References (MISC) https://helpx.adobe.com/security/products/magento/apsb21-30.html - (MISC) https://helpx.adobe.com/security/products/magento/apsb21-30.html - Vendor Advisory

28 Jun 2021, 14:21

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-28 14:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-28563

Mitre link : CVE-2021-28563

CVE.ORG link : CVE-2021-28563


JSON object : View

Products Affected

magento

  • magento
CWE
NVD-CWE-Other CWE-285

Improper Authorization