ZeroHour

CVE-2021-36012

CVSS 3.1
6.5 medium
EPSS
2%p80
Published
()
Modified
Description

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a business logic error in the placeOrder graphql mutation. An authenticated attacker can leverage this vulnerability to altar the price of an item.

Vendors
adobe
Products
adobe commerce, magento open source
Ecosystems
E-commerce
Weakness
CWE-840
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.