First published: Tue Oct 12 2021(Updated: )
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to customer cart by an unauthenticated attacker. Access to the admin console is not required for successful exploitation.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Commerce | <=2.3.7 | |
Adobe Commerce | =2.3.7-p1 | |
Adobe Commerce | =2.4.2 | |
Adobe Commerce | =2.4.2-p1 | |
Adobe Commerce | =2.4.2-p2 | |
Adobe Commerce | =2.4.3 | |
Adobe Magento Open Source | <=2.3.7 | |
Adobe Magento Open Source | =2.3.7-p1 | |
Adobe Magento Open Source | =2.4.2 | |
Adobe Magento Open Source | =2.4.2-p1 | |
Adobe Magento Open Source | =2.4.2-p2 | |
Adobe Magento Open Source | =2.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-39864.
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by this vulnerability.
The severity of CVE-2021-39864 is medium, with a CVSS score of 6.5.
Successful exploitation of CVE-2021-39864 could lead to unauthorized addition to a customer's cart by an unauthenticated attacker.
To fix CVE-2021-39864, it is recommended to update to the latest version of Adobe Commerce or Adobe Magento Open Source.