PT-2021-6363 · Adobe · Magento Commerce

Published

2021-08-11

·

Updated

2024-03-06

·

CVE-2021-36023

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Magento Commerce versions 2.4.2 and earlier Magento Commerce versions 2.4.2-p1 and earlier Magento Commerce versions 2.3.7 and earlier
Description The issue is related to an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution. The vulnerability is also described as related to the failure to neutralize special elements used in operating system commands, which can allow a remote attacker to execute arbitrary code.
Recommendations For versions 2.4.2 and earlier, update to a version that includes a fix for the XML Injection vulnerability in the Widgets Update Layout. For versions 2.4.2-p1 and earlier, update to a version that includes a fix for the XML Injection vulnerability in the Widgets Update Layout. For versions 2.3.7 and earlier, update to a version that includes a fix for the XML Injection vulnerability in the Widgets Update Layout. As a temporary workaround, consider disabling the Widgets Update Layout feature until a patch is available.

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2022-01389
BIT-MAGENTO-2021-36023
CVE-2021-36023
GHSA-8CJG-F53M-8M9Q

Affected Products

Magento Commerce