CVE-2021-21015: Magento Commerce Unauthorized Data Modification Could Lead to Arbitrary Code Execution
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command injection via the customer attribute save controller. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21015?
The severity of CVE-2021-21015 is high.
Which versions of Magento are affected by CVE-2021-21015?
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier), and 2.3.6 (and earlier) are affected by CVE-2021-21015.
What is the vulnerability in CVE-2021-21015?
CVE-2021-21015 is an OS command injection vulnerability via the customer attribute save controller in Magento.
What is the potential impact of CVE-2021-21015?
Successful exploitation of CVE-2021-21015 could lead to arbitrary code execution by an authenticated attacker.
How can I mitigate CVE-2021-21015?
To mitigate CVE-2021-21015, ensure that you have updated to the latest version of Magento that includes the security patch provided by Adobe.