CVE-2021-36024: Magento Commerce Improper Neutralization of Special Elements Used In A Command
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special Elements Used In A Command via the Data collection endpoint. An attacker with admin privileges can upload a specially crafted file to achieve remote code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36024?
The severity of CVE-2021-36024 is critical with a CVSS score of 7.2.
Which versions of Magento Commerce are affected by CVE-2021-36024?
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) are affected by CVE-2021-36024.
What is the vulnerability in Magento Commerce?
CVE-2021-36024 is an Improper Neutralization of Special Elements Used In A Command vulnerability in Magento Commerce.
What can an attacker achieve with CVE-2021-36024?
An attacker with admin privileges can upload a specially crafted file to achieve remote code execution.
Where can I find more information about CVE-2021-36024?
You can find more information about CVE-2021-36024 at the following link: [CVE-2021-36024](https://helpx.adobe.com/security/products/magento/apsb21-64.html)