High severity8.1NVD Advisory· Published Jan 13, 2021· Updated Jun 17, 2026
CVE-2021-21013
CVE-2021-21013
Description
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the customer API module. Successful exploitation could lead to sensitive information disclosure and update arbitrary information on another user's account.
Affected products
4<=2.4.1, <=2.4.0-p1, <=2.3.6+ 2 more
- (no CPE)range: <=2.4.1, <=2.4.0-p1, <=2.3.6
- cpe:2.3:a:adobe:magento:*:*:*:*:commerce:*:*:*range: <=2.4.1
- cpe:2.3:a:adobe:magento:*:*:*:*:open_source:*:*:*range: >=2.4.1
- Range: unspecified
Patches
Vulnerability mechanics
References
1- helpx.adobe.com/security/products/magento/apsb21-08.htmlnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.