CVE-2021-21030: Magento Commerce Stored Cross-site Scripting Could Lead To Arbitrary Javascript Execution
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting (XSS) in the customer address upload feature. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Exploitation of this issue requires user interaction.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21030?
CVE-2021-21030 is a stored cross-site scripting (XSS) vulnerability in Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier), and 2.3.6 (and earlier).
How does the vulnerability CVE-2021-21030 impact Magento?
The vulnerability CVE-2021-21030 allows an attacker to execute arbitrary JavaScript code in the victim's browser through the customer address upload feature.
How can an attacker exploit the vulnerability CVE-2021-21030?
An attacker can exploit the vulnerability CVE-2021-21030 by uploading a malicious customer address file that contains JavaScript code.
What is the severity of CVE-2021-21030?
The severity of CVE-2021-21030 is high with a CVSS score of 8.1.
How can I fix the vulnerability CVE-2021-21030 in my Magento installation?
To fix the vulnerability CVE-2021-21030, you should update your Magento installation to the latest version available, which includes the necessary security patches.