Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Xenx

#51750de 53,633
4.3CVSS total
Vulnerabilidades · 1
PT-2023-12036
4.3
2023-01-26
Unknown · Magneto Lts · CVE-2021-21395
**Name of the Vulnerable Software and Affected Versions** Magneto LTS versions prior to 19.4.22 Magneto LTS versions prior to 20.0.19 **Description** The password reset form in Magneto LTS is vulnerable to Cross-Site Request Forgery (CSRF) between the time the reset password link is clicked and the user submits a new password. **Recommendations** For versions prior to 19.4.22, update to version 19.4.22 to resolve the issue. For versions prior to 20.0.19, update to version 20.0.19 to resolve the issue.