CVE-2021-36036: Magento Commerce Media Gallery Upload Improper Access Control Could Lead To Remote Code Execution
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within Magento's Media Gallery Upload workflow. By storing a specially crafted file in the website gallery, an authenticated attacker with administrative privilege can gain access to delete the .htaccess file. This could result in the attacker achieving remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Magento vulnerability?
The vulnerability ID of this Magento vulnerability is CVE-2021-36036.
What is the severity of CVE-2021-36036?
The severity of CVE-2021-36036 is high.
Which versions of Magento are affected by CVE-2021-36036?
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) are affected by CVE-2021-36036.
What is the impact of CVE-2021-36036?
CVE-2021-36036 allows an authenticated attacker with administrative privileges to upload a specially crafted file, leading to an improper access control vulnerability within Magento's Media Gallery.
Is there a fix for CVE-2021-36036?
Yes, Adobe has released a security update to address CVE-2021-36036. It is recommended to update Magento to the latest version available.