Miggo Logo

CVE-2021-28556: Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies

6.9

CVSS Score
3.1

Basic Information

EPSS Score
0.9714%
Published
5/24/2022
Updated
2/10/2025
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
magento/community-editioncomposer>= 2.4.0, < 2.4.2-p12.4.2-p1
magento/community-editioncomposer< 2.3.72.3.7
magento/project-community-editioncomposer<= 2.0.2

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

M***nto v*rsions *.*.* (*n* **rli*r), *.*.*-p* (*n* **rli*r) *n* *.*.*-p* (*n* **rli*r) *r* *****t** *y * *OM-**s** *ross-Sit* S*riptin* vuln*r**ility on m***-m*ss***s *ooki*s. Su***ss*ul *xploit*tion *oul* l*** to *r*itr*ry J*v*S*ript *x**ution *y *

Reasoning

No *n*lysis *v*il**l*