Description
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability during the checkout process. An unauthenticated attacker can leverage this vulnerability to alter the price of items.
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://helpx.adobe.com/security/products/magento/apsb21-64.html
Scores
CVSS v3
7.5
EPSS
0.0143
EPSS Percentile
80.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-20
Status
published
Products (6)
adobe/adobe_commerce
2.4.2 p1
adobe/adobe_commerce
2.3.0 - 2.3.7
adobe/magento_open_source
2.4.2 p1
adobe/magento_open_source
2.3.0 - 2.3.7
magento/community-edition
0 - 2.3.7-p1Packagist
magento/project-community-edition
0Packagist
Published
Sep 01, 2021
Tracked Since
Feb 18, 2026