Vulnerability Details CVE-2021-36038
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability in the Multishipping Module. An authenticated attacker could leverage this vulnerability to achieve sensitive information disclosure.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 79.9%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2021-36038
-
cpe:2.3:a:adobe:adobe_commerce:*
-
cpe:2.3:a:adobe:adobe_commerce:2.4.2
-
cpe:2.3:a:adobe:magento_open_source:2.3.7
-
cpe:2.3:a:adobe:magento_open_source:2.4.0
-
cpe:2.3:a:adobe:magento_open_source:2.4.1
-
cpe:2.3:a:adobe:magento_open_source:2.4.2