← Vulnerability feed

Vulnerability record · CVE-2021-21029 · published 11 February 2021

CVE-2021-21029: Magento admin reflected XSS via file parameter

MMagento · Magento

Magento versions 2.4.1 and earlier, 2.4.0-p1 and earlier, and 2.3.6 and earlier contain a reflected cross-site scripting flaw reached through the 'file' parameter. Because the vulnerable path sits in the admin console, an attacker must first get an authenticated administrator to trigger the crafted request, after which arbitrary JavaScript runs in that admin's browser.

4.8 CVSS 3.1 Medium EPSS 85% · top 0.3% CWE-79 · Cross-site scripting
4.8CVSS 3.1 base score, v2 3.5
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Access to the admin console is required for successful exploitation.

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityThe flaw requires an authenticated admin and user interaction and yields limited confidentiality and integrity impact, but the high EPSS score and admin-console target keep it worth prompt patching.

What it is

Magento versions 2.4.1 and earlier, 2.4.0-p1 and earlier, and 2.3.6 and earlier contain a reflected cross-site scripting flaw reached through the 'file' parameter. Because the vulnerable path sits in the admin console, an attacker must first get an authenticated administrator to trigger the crafted request, after which arbitrary JavaScript runs in that admin's browser.

Impact

An attacker who lands the payload gains script execution in an administrator's browser session, which can be used to read or alter admin-visible data and perform actions as that administrator. The scope change in the CVSS vector reflects that the injected script can affect resources beyond the vulnerable component.

Attack surface

Reached over the network through a crafted request containing the 'file' parameter; the vector shows high privileges required (PR:H) and user interaction required (UI:R), meaning an authenticated admin must be induced to follow or submit the crafted link.

Exploitation

Not listed in CISA KEV and no public exploit or exploitation tags appear in the references, which are vendor advisories only; EPSS is high at 0.84641 (99.7th percentile), indicating elevated predicted likelihood despite the absence of confirmed in-the-wild use.

What to do

  • Apply the vendor fix from Adobe security bulletin APSB21-08 for Magento, upgrading to a patched release.
  • If immediate patching is not possible, restrict and monitor admin console access to trusted networks and accounts.
  • Enforce output encoding and input validation on the 'file' parameter and similar admin request parameters.
  • Deploy a WAF or CSP that blocks reflected script execution on admin endpoints.
  • Train administrators not to open unsolicited links or attachments that target the admin console.

Detection

  • Search web and proxy logs for requests to admin paths carrying script-like content in the 'file' parameter.
  • Alert on reflected payload strings (script tags, event handlers, javascript: URIs) appearing in admin request parameters.
  • Monitor admin sessions for anomalous actions or requests following a suspicious link click.
  • Review WAF and CSP violation logs for blocked inline script execution on admin pages.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21029 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-34256Adobe commerce improper authorization vulnerabilityAdobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerabilit…EPSS 2.1%9.8CVE-2020-9664Magento deserialization of untrusted data vulnerabilityMagento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could lead to arbit…EPSS 8.4%9.8CVE-2020-9583Magento command injection vulnerabilityMagento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerabili…EPSS 5.7%9.8CVE-2020-9585Magento vulnerabilityMagento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mit…EPSS 4.9%9.8CVE-2020-9630Magento vulnerabilityMagento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error vulnerab…EPSS 4.0%9.8CVE-2020-9631Magento vulnerabilityMagento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vu…EPSS 7.4%9.8CVE-2020-9632Magento vulnerabilityMagento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vu…EPSS 7.4%9.8CVE-2020-9576Magento command injection vulnerabilityMagento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerabili…EPSS 5.7%

Source: NIST National Vulnerability Database (record CVE-2021-21029), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.