CVE-2021-36022: Magento Commerce Widgets Update Layout XML Injection Vulnerability Could Lead To Remote Code Execution
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-36022?
CVE-2021-36022 is an XML Injection vulnerability in Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier).
How does CVE-2021-36022 affect Magento Commerce?
CVE-2021-36022 allows an attacker with admin privileges to trigger a specially crafted script, leading to remote code execution.
What is the severity of CVE-2021-36022?
CVE-2021-36022 has a severity rating of 7.2, which is classified as critical.
Which versions of Magento Commerce are affected by CVE-2021-36022?
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) are affected by CVE-2021-36022.
How can I fix CVE-2021-36022?
To fix CVE-2021-36022, update to the latest version of Magento Commerce (2.4.3 or 2.3.8) or apply the available patches provided by Magento.