CVE-2021-36012

EUVD-2021-22645
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a business logic error in the placeOrder graphql mutation. An authenticated attacker can leverage this vulnerability to altar the price of an item.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
adobeCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
Affected Products (NVD)
VendorProductVersion
adobeadobe_commerce
2.3.0 ≤
𝑥
≤ 2.3.7
adobeadobe_commerce
2.4.0 ≤
𝑥
≤ 2.4.2
adobeadobe_commerce
2.4.2:p1
adobemagento_open_source
2.3.0 ≤
𝑥
≤ 2.3.7
adobemagento_open_source
2.4.0 ≤
𝑥
≤ 2.4.2
adobemagento_open_source
2.4.2:p1
𝑥
= Vulnerable software versions
Common Weakness Enumeration