CVE-2021-21027

Cross-Site Request Forgery (CSRF) in packagist/magento/community-edition

Identifiers

CVE-2021-21027

Package Slug

packagist/magento/community-edition

Vulnerability

Cross-Site Request Forgery (CSRF)

Description

Magento is vulnerable to Cross-Site Request Forger. Successful exploitation could lead to unauthorized modification of customer metadata by an unauthenticated attacker. Access to the admin console is not required for successful exploitation.

Affected Versions

All versions before 2.3.6, all versions starting from 2.4.0 up to 2.4.1

Solution

Upgrade to versions 2.3.6, 2.4.1-p1 or above.

Last Modified

2021-02-18

source