CVE-2021-28567: Magento Commerce improper authorization allows an authenticated user to perform certain functions without permission
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in the customers module. Successful exploitation could allow a low-privileged user to modify customer data. Access to the admin console is required for successful exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Magento security vulnerability?
The vulnerability ID for this Magento security vulnerability is CVE-2021-28567.
What is the severity of CVE-2021-28567?
CVE-2021-28567 has a severity rating of 6.5, classified as medium.
What versions of Magento are affected by CVE-2021-28567?
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier), and 2.3.6-p1 (and earlier) are affected by CVE-2021-28567.
What is the impact of CVE-2021-28567?
Successful exploitation of CVE-2021-28567 could allow a low-privileged user to modify customer data in Magento.
Is access to the admin console required for exploiting CVE-2021-28567?
Yes, access to the admin console is required for exploiting CVE-2021-28567.