CVE-2021-36040: Magento Commerce Improper Input Validation Could Lead To Remote Code Execution
Published Sep 1, 2021
·Updated
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges can upload a specially crafted file to bypass file extension restrictions and could lead to remote code execution.
Affected Software
6 affected components
Adobe Adobe Commerce>=2.3.0<=2.3.7
Adobe Adobe Commerce>=2.4.0<=2.4.2
Adobe Adobe Commerce=2.4.2-p1
Adobe Magento Open Source>=2.3.0<=2.3.7
Adobe Magento Open Source>=2.4.0<=2.4.2
Adobe Magento Open Source=2.4.2-p1
Remediation
Event History
Sep 1, 2021
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36040.
2
What is the severity of CVE-2021-36040?
The severity of CVE-2021-36040 is critical with a severity value of 7.2.
3
Which versions of Magento Commerce are affected?
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) are affected.
4
What is the impact of CVE-2021-36040?
An attacker with admin privileges can upload a specially crafted file to bypass file extension restrictions and could lead to remote code execution.
5
How can I fix the vulnerability?
Apply the necessary security patches provided by Adobe to fix the vulnerability.