CVE-2021-21013

Description

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the customer API module. Successful exploitation could lead to sensitive information disclosure and update arbitrary information on another users account.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.645

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-21012,CVE-2021-21013 are affected in Adobe Bridge (x64) 10.0.3(x64)Windows
Vulnerabilities CVE-2021-21012,CVE-2021-21013 are affected in Adobe Bridge 10.0.3Windows
Multiple Vulnerabilities are affected in Adobe Bridge 11.0.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234