← All CVEs

CVE-2021-21029

medium · 4.8

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Access to the admin console is required for successful exploitation.

4.8
CVSS
84.6%
EPSS (exploit prob.)
100th
EPSS percentile
2021-02-11
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
magentomagento< 2.3.6
magentomagento< 2.3.6
magentomagento2.3.6
magentomagento2.3.6
magentomagento2.4.0
magentomagento2.4.0
magentomagento2.4.0
magentomagento2.4.0
magentomagento2.4.1
magentomagento2.4.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-21029