{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-21T21:51:39.084","vulnerabilities":[{"cve":{"id":"CVE-2021-21024","sourceIdentifier":"psirt@adobe.com","published":"2021-02-11T20:15:14.450","lastModified":"2024-11-21T05:47:25.397","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a blind SQL injection vulnerability in the Search module. Successful exploitation could lead to unauthorized access to restricted resources by an unauthenticated attacker. Access to the admin console is required for successful exploitation."},{"lang":"es","value":"Magento versiones 2.4.1 (y anteriores), versiones 2.4.0-p1 (y anteriores) y versiones 2.3.6 (y anteriores), están afectadas por una vulnerabilidad de inyección SQL ciega en el módulo Search.&#xa0;Una explotación con éxito podría conllevar a un acceso no autorizado a recursos restringidos por parte de un atacante no autenticado.&#xa0;Es requerido un acceso a la consola de administración para una explotación con éxito"}],"metrics":{"cvssMetricV30":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*","versionEndExcluding":"2.3.6","matchCriteriaId":"14B6B496-E849-4935-B3D8-8BDB8DDD59A3"},{"vulnerable":true,"criteria":"cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*","versionEndExcluding":"2.3.6","matchCriteriaId":"79C3A2B0-AE14-4D0F-BEE2-82FC00BE6087"},{"vulnerable":true,"criteria":"cpe:2.3:a:magento:magento:2.3.6:-:*:*:commerce:*:*:*","matchCriteriaId":"F9C60780-1213-4D06-A4C4-CC915C952B7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:magento:magento:2.3.6:-:*:*:open_source:*:*:*","matchCriteriaId":"3CCEDD72-7195-495C-A9B6-9D18BA9756F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:magento:magento:2.4.0:-:*:*:commerce:*:*:*","matchCriteriaId":"05F799AA-CDC0-409F-BB7E-CB941D6FB189"},{"vulnerable":true,"criteria":"cpe:2.3:a:magento:magento:2.4.0:-:*:*:open_source:*:*:*","matchCriteriaId":"600AA27A-D2A8-41C3-8631-74ECF7453E78"},{"vulnerable":true,"criteria":"cpe:2.3:a:magento:magento:2.4.0:p1:*:*:commerce:*:*:*","matchCriteriaId":"67683B07-34CD-4DD2-A6C9-C71733007397"},{"vulnerable":true,"criteria":"cpe:2.3:a:magento:magento:2.4.0:p1:*:*:open_source:*:*:*","matchCriteriaId":"ECA32B69-E9D8-4C01-ACDC-E0F885D937FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:magento:magento:2.4.1:-:*:*:commerce:*:*:*","matchCriteriaId":"80860D39-0D51-47B3-BA92-F473ADA1BBC3"},{"vulnerable":true,"criteria":"cpe:2.3:a:magento:magento:2.4.1:-:*:*:open_source:*:*:*","matchCriteriaId":"2ADFE661-AB9C-4387-AC4F-D14A0717C2B8"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/magento/apsb21-08.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]},{"url":"https://helpx.adobe.com/security/products/magento/apsb21-08.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}