-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| magento/community-edition | composer | < 2.3.6 | 2.3.6 |
| magento/community-edition | composer | = 2.4.0 | 2.4.1 |
| magento/project-community-edition | composer | <= 2.0.2 |
The vulnerability stems from two key factors: 1) Incorrect default permissions in integration configuration (CWE-276) allowing broader API access than intended, and 2) Missing authorization checks (CWE-285) in customer deletion workflows. While exact code isn't available, pattern analysis suggests:
Ongoing coverage of React2Shell