CVE-2021-28584: Magento Commerce path traversal vulnerability in child theme store creation
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Path Traversal vulnerability when creating a store with child theme.Successful exploitation could lead to arbitrary file system write by an authenticated attacker. Access to the admin console is required for successful exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-28584?
CVE-2021-28584 is a Path Traversal vulnerability in Magento versions 2.4.2 and earlier, 2.4.1-p1 and earlier, and 2.3.6-p1 and earlier.
How does the CVE-2021-28584 vulnerability affect Magento?
The CVE-2021-28584 vulnerability allows an authenticated attacker to perform arbitrary file system write when creating a store with child theme in Magento.
What is the severity of CVE-2021-28584?
CVE-2021-28584 has a severity rating of 7.2 (High) out of 10.
Which versions of Magento are affected by CVE-2021-28584?
Magento versions 2.4.2 and earlier, 2.4.1-p1 and earlier, and 2.3.6-p1 and earlier are affected by the CVE-2021-28584 vulnerability.
How can I fix the CVE-2021-28584 vulnerability in Magento?
To fix the CVE-2021-28584 vulnerability in Magento, you should update to the latest version provided by the vendor and apply any necessary security patches.