Show filters
32 Total Results
Displaying 31-32 of 32
Sort by:
Attacker Value
Unknown
CVE-2021-36044
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An unauthenticated attacker could abuse this vulnerability to cause a server-side denial-of-service using a GraphQL field.
0
Attacker Value
Unknown
CVE-2021-21012
Disclosure Date: January 12, 2021 (last updated February 22, 2025)
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the checkout module. Successful exploitation could lead to sensitive information disclosure.
0