Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting vulnerability in the admin console. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Access to the admin console is required for successful exploitation.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: adobe

Published: 2021-02-09T00:00:00

Updated: 2021-02-11T19:29:31

Reserved: 2020-12-18T00:00:00


Link: CVE-2021-21023

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2021-02-11T20:15:14.387

Modified: 2023-11-07T03:29:17.553


Link: CVE-2021-21023

JSON object: View

cve-icon Redhat Information

No data.

CWE