A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can cause unwanted items to be added to a shopper's cart due to an insufficiently robust anti-CSRF token implementation.
{
"cpe": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
"extracted_events": [
{
"introduced": "2.1.0"
},
{
"fixed": "2.1.18"
},
{
"introduced": "2.2.0"
},
{
"fixed": "2.2.9"
},
{
"introduced": "2.3.0"
},
{
"fixed": "2.3.2"
}
],
"source": "CPE_RANGE"
}{
"cpe": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
"extracted_events": [
{
"introduced": "2.1.0"
},
{
"fixed": "2.1.18"
},
{
"introduced": "2.2.0"
},
{
"fixed": "2.2.9"
},
{
"introduced": "2.3.0"
},
{
"fixed": "2.3.2"
}
],
"source": "CPE_RANGE"
}