CVE-2021-39864
15.10.2021, 15:15
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to customer cart by an unauthenticated attacker. Access to the admin console is not required for successful exploitation.
Vendor | Product | Version |
---|---|---|
adobe | commerce | 𝑥 ≤ 2.3.7 |
adobe | commerce | 2.3.7:p1 |
adobe | commerce | 2.4.2 |
adobe | commerce | 2.4.2:p1 |
adobe | commerce | 2.4.2:p2 |
adobe | commerce | 2.4.3 |
adobe | magento_open_source | 𝑥 ≤ 2.3.7 |
adobe | magento_open_source | 2.3.7:p1 |
adobe | magento_open_source | 2.4.2 |
adobe | magento_open_source | 2.4.2:p1 |
adobe | magento_open_source | 2.4.2:p2 |
adobe | magento_open_source | 2.4.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration