Magento stored cross-site scripting vulnerability in the customer address upload feature

Description

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a stored cross-site scripting vulnerability in the customer address upload feature that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

Basic information

Type
reviewed
Severity
medium
Advisory on GitHub
Open advisory ↗
Repository advisory
Source code
Browse source ↗
Published (advisory)
2022-05-24 22:28:26 UTC
Updated
2025-11-06 20:57:57 UTC
GitHub reviewed
2025-11-06 20:57:57 UTC
NVD published
2021-09-01

EPSS Score

Score Percentile
1.53% 80.86%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

CWEs

CWE id Name
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected packages (5)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
composer magento/project-community-edition <= 2.0.2
composer magento/community-edition < 2.3.7-p1 2.3.7-p1
composer magento/community-edition = 2.3.7
composer magento/community-edition >= 2.4.2-p1, < 2.4.2-p2 2.4.2-p2
composer magento/community-edition = 2.4.2

References

cvelogic Threat Intelligence