CVE-2021-28563: Magento Commerce improper Authorization via the 'Create Customer' endpoint
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper Authorization vulnerability via the 'Create Customer' endpoint. Successful exploitation could lead to unauthorized modification of customer data by an unauthenticated attacker. Access to the admin console is required for successful exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28563?
The severity of CVE-2021-28563 is medium, with a severity value of 6.5.
Which versions of Magento are affected by CVE-2021-28563?
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier), and 2.3.6-p1 (and earlier) are affected by CVE-2021-28563.
What is the vulnerability in Magento related to CVE-2021-28563?
CVE-2021-28563 is an Improper Authorization vulnerability via the 'Create Customer' endpoint in Magento, which allows unauthorized modification of customer data.
How can an attacker exploit CVE-2021-28563?
An unauthenticated attacker can exploit CVE-2021-28563 by exploiting the Improper Authorization vulnerability via the 'Create Customer' endpoint to modify customer data without authorization.
Is there a fix available for CVE-2021-28563?
Yes, a fix is available for CVE-2021-28563. It is recommended to update to a patched version of Magento to mitigate this vulnerability.