Magneto-lts vulnerable to Cross-Site Request Forgery
CVE-2021-21395

4.2MEDIUM

Key Information:

Vendor

Openmage

Vendor
CVE Published:
27 January 2023

What is CVE-2021-21395?

Magneto LTS (Long Term Support) is a community developed alternative to the Magento CE official releases. Versions prior to 19.4.22 and 20.0.19 are vulnerable to Cross-Site Request Forgery. The password reset form is vulnerable to CSRF between the time the reset password link is clicked and user submits new password. This issue is patched in versions 19.4.22 and 20.0.19. There are no workarounds.

Affected Version(s)

magento-lts < 19.4.22 < 19.4.22

magento-lts >= 20.0.0, < 20.0.19 < 20.0.0, 20.0.19

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.