Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting (XSS) in the customer address upload feature. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Exploitation of this issue requires user interaction.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2022-2758 | Magento stored cross-site scripting (XSS) in the customer address upload feature |
![]() |
GHSA-6988-g89m-27vf | Magento stored cross-site scripting (XSS) in the customer address upload feature |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-09-16T19:19:56.211Z
Reserved: 2020-12-18T00:00:00
Link: CVE-2021-21030

No data.

Status : Modified
Published: 2021-02-11T20:15:14.827
Modified: 2024-11-21T05:47:26.037
Link: CVE-2021-21030

No data.

No data.