Medium severity6.5NVD Advisory· Published Jun 28, 2021· Updated Jun 17, 2026
CVE-2021-28563
CVE-2021-28563
Description
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper Authorization vulnerability via the 'Create Customer' endpoint. Successful exploitation could lead to unauthorized modification of customer data by an unauthenticated attacker. Access to the admin console is required for successful exploitation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
magento/community-editionPackagist | >= 2.4.0, < 2.4.2-p1 | 2.4.2-p1 |
magento/community-editionPackagist | < 2.3.7 | 2.3.7 |
Affected products
5- osv-coords2 versions
< 2.3.7+ 1 more
- (no CPE)range: < 2.3.7
- (no CPE)range: >= 2.4.0, < 2.4.2-p1
- Range: unspecified
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-q9xx-4689-gvv5ghsaADVISORY
- helpx.adobe.com/security/products/magento/apsb21-30.htmlnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-28563ghsaADVISORY
- github.com/magento/magento2/commit/1bd5cb8c065e44779526c0b044ce19b884707695ghsaWEB
- github.com/magento/magento2/commit/ed952726c94e401e922e88490e41a536f2d850e7ghsaWEB
News mentions
0No linked articles in our index yet.