CVE-2021-21027
Estado: ModificadaMedia (4.3)—
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via the GraphQL API. Successful exploitation could lead to unauthorized modification of customer metadata by an unauthenticated attacker. Access to the admin console is not required for successful exploitation.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.66%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-352
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-21027",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "psirt@adobe.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@adobe.com",
"affectedData": [
{
"vendor": "Adobe",
"product": "Magento Commerce",
"versions": [
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "2.4.1"
},
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "2.4.0-p1"
},
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "2.3.6"
},
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "None"
}
]
}
]
}
],
"published": "2021-02-11T20:15:14.623",
"references": [
{
"url": "https://helpx.adobe.com/security/products/magento/apsb21-08.html",
"tags": [
"Vendor Advisory"
],
"source": "psirt@adobe.com"
},
{
"url": "https://helpx.adobe.com/security/products/magento/apsb21-08.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@adobe.com",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via the GraphQL API. Successful exploitation could lead to unauthorized modification of customer metadata by an unauthenticated attacker. Access to the admin console is not required for successful exploitation."
},
{
"lang": "es",
"value": "Magento versiones 2.4.1 (y anteriores), versiones 2.4.0-p1 (y anteriores) y versiones 2.3.6 (y anteriores), están afectadas por una vulnerabilidad de tipo cross-site request forgery (CSRF) por medio de la API GraphQL. Una explotación con éxito podría conllevar a modificaciones no autorizadas de los metadatos del cliente por parte de un atacante no autenticado. No es requerido un acceso a la consola de administración para una explotación con éxito"
}
],
"lastModified": "2026-06-17T03:34:41.323",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*",
"vulnerable": true,
"matchCriteriaId": "14B6B496-E849-4935-B3D8-8BDB8DDD59A3",
"versionEndExcluding": "2.3.6"
},
{
"criteria": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "79C3A2B0-AE14-4D0F-BEE2-82FC00BE6087",
"versionEndExcluding": "2.3.6"
},
{
"criteria": "cpe:2.3:a:magento:magento:2.3.6:-:*:*:commerce:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F9C60780-1213-4D06-A4C4-CC915C952B7B"
},
{
"criteria": "cpe:2.3:a:magento:magento:2.3.6:-:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3CCEDD72-7195-495C-A9B6-9D18BA9756F7"
},
{
"criteria": "cpe:2.3:a:magento:magento:2.4.0:-:*:*:commerce:*:*:*",
"vulnerable": true,
"matchCriteriaId": "05F799AA-CDC0-409F-BB7E-CB941D6FB189"
},
{
"criteria": "cpe:2.3:a:magento:magento:2.4.0:-:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "600AA27A-D2A8-41C3-8631-74ECF7453E78"
},
{
"criteria": "cpe:2.3:a:magento:magento:2.4.0:p1:*:*:commerce:*:*:*",
"vulnerable": true,
"matchCriteriaId": "67683B07-34CD-4DD2-A6C9-C71733007397"
},
{
"criteria": "cpe:2.3:a:magento:magento:2.4.0:p1:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ECA32B69-E9D8-4C01-ACDC-E0F885D937FB"
},
{
"criteria": "cpe:2.3:a:magento:magento:2.4.1:-:*:*:commerce:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80860D39-0D51-47B3-BA92-F473ADA1BBC3"
},
{
"criteria": "cpe:2.3:a:magento:magento:2.4.1:-:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2ADFE661-AB9C-4387-AC4F-D14A0717C2B8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@adobe.com"
}