CVE-2021-36031: Magento Commerce Path Traversal In `theme[preview_image]` Parameter Could Lead To Remote Code Execution
Published Sep 1, 2021
·Updated
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a Path Traversal vulnerability via the theme[previewimage] parameter. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.
Affected Software
6 affected components
Adobe Adobe Commerce>=2.3.0<=2.3.7
Adobe Adobe Commerce>=2.4.0<=2.4.2
Adobe Adobe Commerce=2.4.2-p1
Adobe Magento Open Source>=2.3.0<=2.3.7
Adobe Magento Open Source>=2.4.0<=2.4.2
Adobe Magento Open Source=2.4.2-p1
Remediation
Event History
Sep 1, 2021
CVE Published
via MITRE·02:30 PM
Data Sourced
via MITRE·02:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Magento Commerce vulnerability?
The vulnerability ID is CVE-2021-36031.
2
Which versions of Magento Commerce are affected by this vulnerability?
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) are affected.
3
What is the severity of CVE-2021-36031?
The severity of CVE-2021-36031 is high with a severity value of 7.2.
4
How can an attacker exploit this vulnerability?
An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.
5
Is there a fix available for this vulnerability?
Yes, Magento has released patches to address this vulnerability. It is recommended to update to the latest patched version of Magento Commerce.