CVE-2021-28556
28.06.2021, 14:15
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mage-messages cookies. Successful exploitation could lead to arbitrary JavaScript execution by an unauthenticated attacker. User interaction is required for successful exploitation.
Vendor | Product | Version |
---|---|---|
magento | magento | 𝑥 < 2.3.7 |
magento | magento | 𝑥 < 2.3.7 |
magento | magento | 2.4.0 ≤ 𝑥 ≤ 2.4.2 |
magento | magento | 2.4.0 ≤ 𝑥 ≤ 2.4.2 |
𝑥
= Vulnerable software versions