CVE-2021-36025: Magento Commerce Customer Edition Improper Input Validation Could Lead To Remote Code Execution
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability while saving a customer's details with a specially crafted file. An authenticated attacker with admin privileges can leverage this vulnerability to achieve remote code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36025?
The severity of CVE-2021-36025 is critical (7.2).
What is the vulnerability description of CVE-2021-36025?
CVE-2021-36025 is an improper input validation vulnerability in Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) when saving a customer's details with a specially crafted file.
Which versions of Adobe Adobe Commerce are affected by CVE-2021-36025?
Adobe Adobe Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) are affected by CVE-2021-36025.
Which versions of Adobe Magento Open Source are affected by CVE-2021-36025?
Adobe Magento Open Source versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) are affected by CVE-2021-36025.
How can an authenticated attacker exploit CVE-2021-36025?
An authenticated attacker with admin privileges can exploit CVE-2021-36025 by leveraging the improper input validation vulnerability while saving a customer's details with a specially crafted file.