Magento 2.3.7 Open Source Edition

CPE Details

Magento 2.3.7 Open Source Edition
2.3.7
2021-06-30
11h07 +00:00
2021-06-30
12h12 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:magento:magento:2.3.7:*:*:*:open_source:*:*:*

Informations

Vendor

magento

Product

magento

Version

2.3.7

Software Edition

open_source

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-28567 2021-09-08 16h19 +00:00 Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in the customers module. Successful exploitation could allow a low-privileged user to modify customer data. Access to the admin console is required for successful exploitation.
6.5
Medium
CVE-2021-28566 2021-09-08 16h19 +00:00 Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Information Disclosure vulnerability when uploading a modified png file to a product image. Successful exploitation could lead to the disclosure of document root path by an unauthenticated attacker. Access to the admin console is required for successful exploitation.
3.7
Low