CVE-2021-21030
packagist/magento/community-edition
Cross-site Scripting
Magento is vulnerable to a stored cross-site scripting (XSS) in the customer address upload feature. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Exploitation of this issue requires user interaction.
All versions before 2.3.6, all versions starting from 2.4.0 up to 2.4.1
Upgrade to versions 2.3.6, 2.4.1-p1 or above.
2021-02-18
source |