
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability CVE-2021-21395 affects OpenMage/magento-lts, an open-source e-commerce platform. The vulnerability was discovered in versions <= 19.4.21 and <= 20.0.18 of the software. It relates to a security issue where the password reset functionality is not properly protected against well-timed Cross-Site Request Forgery (CSRF) attacks (OpenMage Advisory).
The vulnerability exists in the password reset form functionality, specifically during the time window between when a user clicks the reset password link and when they submit the new password. During this period, the form is vulnerable to CSRF attacks (OpenMage Advisory). The severity of this vulnerability is rated as Low.
If exploited, an attacker could potentially hijack the password reset process during the vulnerable time window, potentially leading to unauthorized password changes. However, the impact is limited by the specific timing requirements of the attack (OpenMage Advisory).
At the time of the advisory, no official patches or workarounds were available. The advisory indicates that a pull request with fixes was forthcoming (OpenMage Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."