CVE-2021-28556

MEDIUM6.9EPSS 23.9%

Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies

Published: 5/24/2022Modified: 2/10/2025
Also known as:GHSA-39ch-rg26-gmq5BIT-magento-2021-28556

Description

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mage-messages cookies. Successful exploitation could lead to arbitrary JavaScript execution by an unauthenticated attacker. User interaction is required for successful exploitation.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.9CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N

References (4)