{"api_version":"1","generated_at":"2026-07-24T02:46:32+00:00","cve":"CVE-2021-21308","urls":{"html":"https://cve.report/CVE-2021-21308","api":"https://cve.report/api/cve/CVE-2021-21308.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-21308","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-21308"},"summary":{"title":"CVE-2021-21308","description":"PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an attacker is able to foreign request and executes customer commands. The problem is fixed in 1.7.7.2","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2021-02-26 20:15:00","updated_at":"2021-03-05 19:04:00"},"problem_types":["CWE-287"],"metrics":[],"references":[{"url":"https://github.com/PrestaShop/PrestaShop/releases/tag/1.7.7.2","name":"https://github.com/PrestaShop/PrestaShop/releases/tag/1.7.7.2","refsource":"MISC","tags":["Release Notes","Third Party Advisory"],"title":"Release PrestaShop 1.7.7.2 · PrestaShop/PrestaShop · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-557h-hf3c-whcg","name":"https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-557h-hf3c-whcg","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"Improper session management for soft logout · Advisory · PrestaShop/PrestaShop · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/PrestaShop/PrestaShop/commit/2f673bd93e313f08c35e74decc105f40dc0b7dee","name":"https://github.com/PrestaShop/PrestaShop/commit/2f673bd93e313f08c35e74decc105f40dc0b7dee","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"Merge pull request from GHSA-557h-hf3c-whcg · PrestaShop/PrestaShop@2f673bd · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-21308","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-21308","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"21308","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"prestashop","cpe5":"prestashop","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"21308","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"prestashop","cpe5":"prestashop","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2021-21308","STATE":"PUBLIC","TITLE":"Improper session management for soft logout"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"PrestaShop","version":{"version_data":[{"version_value":">= 1.5.0, < 1.7.7.2"}]}}]},"vendor_name":"PrestaShop"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an attacker is able to foreign request and executes customer commands. The problem is fixed in 1.7.7.2"}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-287: Improper Authentication"}]}]},"references":{"reference_data":[{"name":"https://github.com/PrestaShop/PrestaShop/releases/tag/1.7.7.2","refsource":"MISC","url":"https://github.com/PrestaShop/PrestaShop/releases/tag/1.7.7.2"},{"name":"https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-557h-hf3c-whcg","refsource":"CONFIRM","url":"https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-557h-hf3c-whcg"},{"name":"https://github.com/PrestaShop/PrestaShop/commit/2f673bd93e313f08c35e74decc105f40dc0b7dee","refsource":"MISC","url":"https://github.com/PrestaShop/PrestaShop/commit/2f673bd93e313f08c35e74decc105f40dc0b7dee"}]},"source":{"advisory":"GHSA-557h-hf3c-whcg","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-02-26 20:15:00","lastModifiedDate":"2021-03-05 19:04:00","problem_types":["CWE-287"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*","versionStartExcluding":"1.5.0.0","versionEndExcluding":"1.7.7.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"21308","Ordinal":"195434","Title":"CVE-2021-21308","CVE":"CVE-2021-21308","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"21308","Ordinal":"1","NoteData":"PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an attacker is able to foreign request and executes customer commands. The problem is fixed in 1.7.7.2","Type":"Description","Title":null},{"CveYear":"2021","CveId":"21308","Ordinal":"2","NoteData":"2021-02-26","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"21308","Ordinal":"3","NoteData":"2021-02-26","Type":"Other","Title":"Modified"}]}}}