CVE-2021-36021: Magento Commerce CMS Page Improper Input Validation Could Lead To Remote Code Execution
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper input validation vulnerability within the CMS page scheduled update feature. An authenticated attacker with administrative privilege could leverage this vulnerability to achieve remote code execution on the system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Magento vulnerability?
The vulnerability ID for this Magento vulnerability is CVE-2021-36021.
Which versions of Magento are affected by this vulnerability?
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) are affected by this vulnerability.
What is the severity of CVE-2021-36021?
The severity of CVE-2021-36021 is high with a CVSS score of 7.2.
What is the impact of this vulnerability?
An authenticated attacker with administrative privilege could leverage this vulnerability to achieve remote code execution.
Is there a patch available for this vulnerability?
Yes, a patch is available. Please refer to the official Magento website for more information.