CVE-2021-36035: Magento Commerce Stock Media Improper Input Validation Could Lead To Remote Code Execution
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges could make a crafted request to the Adobe Stock API to achieve remote code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36035.
Which versions of Magento Commerce are affected by this vulnerability?
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) are affected.
What is the severity of CVE-2021-36035?
The severity of CVE-2021-36035 is critical with a CVSS score of 7.2.
How does this vulnerability occur?
This vulnerability occurs due to improper input validation.
What can an attacker achieve with this vulnerability?
An attacker with admin privileges could achieve remote code execution by making a crafted request to the Adobe Stock API.
How can I fix CVE-2021-36035?
Upgrade to Magento Commerce versions 2.4.3, 2.4.3-p1, or 2.3.8 to fix this vulnerability.