CVE-2021-36033: Magento Commerce Widgets Module XML Injection Vulnerability Could Lead To Remote Code Execution
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36033.
What is the severity level of CVE-2021-36033?
The severity level of CVE-2021-36033 is critical.
Which software versions are affected by CVE-2021-36033?
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) are affected by CVE-2021-36033.
What is the impact of CVE-2021-36033?
CVE-2021-36033 allows an attacker with admin privileges to trigger a specially crafted script and achieve remote code execution.
Where can I find more information about CVE-2021-36033?
You can find more information about CVE-2021-36033 at the following link: [Adobe Security Bulletin APSB21-64](https://helpx.adobe.com/security/products/magento/apsb21-64.html)