Looking for the vulnerability index of Invicti's legacy products?
Magento Improper Access Control Vulnerability (CVE-2021-21020) - Vulnerability Database

Magento Improper Access Control Vulnerability (CVE-2021-21020)

Description

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an access control bypass vulnerability in the Login as Customer module. Successful exploitation could lead to unauthorized access to restricted resources.

References

Related Vulnerabilities