VYPR

Packagist (Composer) package

magento/community-edition

pkg:composer/magento/community-edition

Vulnerabilities (355)

  • CVE-2021-36029CriSep 1, 2021
    affected < 2.3.7-p1fixed 2.3.7-p1

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.

  • CVE-2021-36028CriSep 1, 2021
    affected < 2.3.7-p1fixed 2.3.7-p1

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability when saving a configurable product. An attacker with admin privileges can trigger a specially crafted script to achieve remote code executi

  • CVE-2021-36027MedSep 1, 2021
    affected < 2.3.7-p1fixed 2.3.7-p1

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a stored cross-site scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be execu

  • CVE-2021-36026MedSep 1, 2021
    affected < 2.3.7-p1fixed 2.3.7-p1

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a stored cross-site scripting vulnerability in the customer address upload feature that could be abused by an attacker to inject malicious scripts into vulnerable form fi

  • CVE-2021-36025CriSep 1, 2021
    affected < 2.3.7-p1fixed 2.3.7-p1

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability while saving a customer's details with a specially crafted file. An authenticated attacker with admin privileges can leverage t

  • CVE-2021-36024CriSep 1, 2021
    affected < 2.3.7-p1fixed 2.3.7-p1

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special Elements Used In A Command via the Data collection endpoint. An attacker with admin privileges can upload a specially crafted file t

  • CVE-2021-36022CriSep 1, 2021
    affected < 2.3.7-p1fixed 2.3.7-p1

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.

  • CVE-2021-36020HigSep 1, 2021
    affected < 2.3.7-p1fixed 2.3.7-p1

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the 'City' field. An unauthenticated attacker can trigger a specially crafted script to achieve remote code execution.

  • CVE-2021-36012MedSep 1, 2021
    affected < 2.3.7-p1fixed 2.3.7-p1

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a business logic error in the placeOrder graphql mutation. An authenticated attacker can leverage this vulnerability to altar the price of an item.

  • CVE-2021-28585MedJun 28, 2021
    affected >= 2.4.0, < 2.4.2-p1fixed 2.4.2-p1

    Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper input validation vulnerability in the New customer WebAPI.Successful exploitation could allow an attacker to send unsolicited spam e-mails.

  • CVE-2021-28584MedJun 28, 2021
    affected >= 2.4.0, < 2.4.2-p1fixed 2.4.2-p1

    Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Path Traversal vulnerability when creating a store with child theme.Successful exploitation could lead to arbitrary file system write by an authenticated attacker. Access to

  • CVE-2021-28583HigJun 28, 2021
    affected >= 2.4.0, < 2.4.2-p1fixed 2.4.2-p1

    Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Violation of Secure Design Principles vulnerability in RMA PDF filename formats. Successful exploitation could allow an attacker to get unauthorized access to restricted reso

  • CVE-2021-28563MedJun 28, 2021
    affected >= 2.4.0, < 2.4.2-p1fixed 2.4.2-p1

    Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper Authorization vulnerability via the 'Create Customer' endpoint. Successful exploitation could lead to unauthorized modification of customer data by an unauthenticat

  • CVE-2021-28556MedJun 28, 2021
    affected >= 2.4.0, < 2.4.2-p1fixed 2.4.2-p1

    Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mage-messages cookies. Successful exploitation could lead to arbitrary JavaScript execution by an unauthenticated attacker. Us

  • CVE-2021-21014CriFeb 11, 2021
    affected < 2.3.6-p1fixed 2.3.6-p1

    Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for succes

  • CVE-2021-21032MedFeb 11, 2021
    affected >= 2.4.0, < 2.4.1-p1fixed 2.4.1-p1

    Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation of this issue could lead to unauthorized access to restricted resources. Access to the admin console is not required for succes

  • CVE-2021-21031MedFeb 11, 2021
    affected >= 2.4.0, < 2.4.1-p1fixed 2.4.1-p1

    Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation could lead to unauthorized access to restricted resources. Access to the admin console is not required for successful exploitat

  • CVE-2021-21030HigFeb 11, 2021
    affected < 2.3.6fixed 2.3.6

    Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting (XSS) in the customer address upload feature. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Exploit

  • CVE-2021-21029MedFeb 11, 2021
    affected < 2.3.6-p1fixed 2.3.6-p1

    Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Access to the ad

  • CVE-2021-21027MedFeb 11, 2021
    affected < 2.3.6-p1fixed 2.3.6-p1

    Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via the GraphQL API. Successful exploitation could lead to unauthorized modification of customer metadata by an unauthenticated a

Page 9 of 18