CVE-2021-36024
published 2021-09-01CVE-2021-36024: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special Elements…
PriorityP346high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
2.89%
85.2th percentile
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special Elements Used In A Command via the Data collection endpoint. An attacker with admin privileges can upload a specially crafted file to achieve remote code execution.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_commerce | — | — |
| adobe | adobe_commerce | 2.3.0 – 2.3.7 | — |
| adobe | adobe_commerce | 2.4.0 – 2.4.2 | — |
| adobe | magento_commerce | unspecified – 2.4.2 | — |
| adobe | magento_open_source | — | — |
| adobe | magento_open_source | 2.3.0 – 2.3.7 | — |
| adobe | magento_open_source | 2.4.0 – 2.4.2 | — |
| magento | community-edition | >= 0 < 2.3.7-p1 | 2.3.7-p1 |
| magento | community-edition | >= 2.4.2-p1 < 2.4.2-p2 | 2.4.2-p2 |
| magento | project-community-edition | 0 – 2.0.2 | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Magento is affected by an os command injection via the Data collection endpoint
ghsa·2022-05-24
CVE-2021-36024 [HIGH] CWE-77 Magento is affected by an os command injection via the Data collection endpoint
Magento is affected by an os command injection via the Data collection endpoint
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special Elements Used In A Command via the Data collection endpoint. An attacker with admin privileges can upload a specially crafted file to achieve remote code execution.
OSV
Magento is affected by an os command injection via the Data collection endpoint
osv·2022-05-24
CVE-2021-36024 [HIGH] Magento is affected by an os command injection via the Data collection endpoint
Magento is affected by an os command injection via the Data collection endpoint
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special Elements Used In A Command via the Data collection endpoint. An attacker with admin privileges can upload a specially crafted file to achieve remote code execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-09-01
Published