CVE-2021-36039: Magento Commerce `quoteId` parameter Incorrect Authorization Vulnerability Could Lead To Information Disclosure
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability via the quoteId parameter. An attacker can abuse this vulnerability to disclose sensitive information.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Magento Commerce vulnerability?
The vulnerability ID for this Magento Commerce vulnerability is CVE-2021-36039.
Which versions of Magento Commerce are affected by this vulnerability?
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) are affected by this vulnerability.
What is the severity of CVE-2021-36039?
The severity of CVE-2021-36039 is medium with a CVSS score of 6.5.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by abusing the `quoteId` parameter to disclose sensitive information.
Where can I find more information about CVE-2021-36039?
You can find more information about CVE-2021-36039 at the following link: [CVE-2021-36039](https://helpx.adobe.com/security/products/magento/apsb21-64.html).