CVE-2021-21030
Magento Commerce Stored Cross-site Scripting Could Lead To Arbitrary Javascript Execution
8.1
HIGH
CVSS 3.1
EPSS 6.3%
Description
Magento versions 2.4.1 (and earlier), 2.4.0 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting (XSS) in the customer address upload feature. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Exploitation of this issue requires user interaction.
How to fix CVE-2021-21030
To remediate CVE-2021-21030, upgrade the affected package to a fixed version below.
- —upgrade to 2.3.6 or later
- —upgrade to 2.3.6 or later
- —no fix listed
Is CVE-2021-21030 being exploited?
Moderate — EPSS is 6.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (3)
- from 0, < 2.3.6, >= 2.4.0, < 2.4.1
- from 0, < 2.3.6
- from 0, <= 2.0.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |