PT-2023-12036 · Unknown · Magneto Lts
Xenx
·
Publicado
2023-01-26
·
Atualizado
2023-02-07
·
CVE-2021-21395
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Magneto LTS versions prior to 19.4.22
Magneto LTS versions prior to 20.0.19
Description
The password reset form in Magneto LTS is vulnerable to Cross-Site Request Forgery (CSRF) between the time the reset password link is clicked and the user submits a new password.
Recommendations
For versions prior to 19.4.22, update to version 19.4.22 to resolve the issue.
For versions prior to 20.0.19, update to version 20.0.19 to resolve the issue.
Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Magneto Lts