CVE-2021-36012

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a business logic error in the placeOrder graphql mutation. An authenticated attacker can leverage this vulnerability to altar the price of an item.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
adobeCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
VendorProductVersion
adobeadobe_commerce
2.3.0 ≤
𝑥
≤ 2.3.7
adobeadobe_commerce
2.4.0 ≤
𝑥
≤ 2.4.2
adobeadobe_commerce
2.4.2:p1
adobemagento_open_source
2.3.0 ≤
𝑥
≤ 2.3.7
adobemagento_open_source
2.4.0 ≤
𝑥
≤ 2.4.2
adobemagento_open_source
2.4.2:p1
𝑥
= Vulnerable software versions
Common Weakness Enumeration