Cross-site Request Forgery (CSRF) Affecting magento/community-edition package, versions <2.3.6-p1 >=2.4.0, <2.4.2


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team

    Threat Intelligence

    EPSS
    0.07% (32nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-PHP-MAGENTOCOMMUNITYEDITION-1071041
  • published 10 Feb 2021
  • disclosed 10 Feb 2021
  • credit Lachlan Davidson

How to fix?

Upgrade magento/community-edition to version 2.3.6-p1, 2.4.2 or higher.

Overview

magento/community-edition is a modern cloud eCommerce platform.

Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF). It exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website, such as change metadata of website customers.

CVSS Scores

version 3.1
Expand this section

Snyk

Recommended
8.2 high
  • Attack Vector (AV)
    Network
  • Attack Complexity (AC)
    Low
  • Privileges Required (PR)
    None
  • User Interaction (UI)
    Required
  • Scope (S)
    Changed
  • Confidentiality (C)
    Low
  • Integrity (I)
    High
  • Availability (A)
    None
Expand this section

NVD

4.3 medium