7.2

CVE-2021-36021

Magento Commerce CMS Page Improper Input Validation Could Lead To Remote Code Execution

Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper input validation vulnerability within the CMS page scheduled update feature. An authenticated attacker with administrative privilege could leverage this vulnerability to achieve remote code execution on the system. 
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Magento ≫ Magento SwEdition commerce Version < 2.3.7
Magento ≫ Magento SwEdition open_source Version < 2.3.7
Magento ≫ Magento SwEdition commerce Version >= 2.4.0 < 2.4.2
Magento ≫ Magento SwEdition open_source Version >= 2.4.0 < 2.4.2
Magento ≫ Magento Version 2.3.7 Update - SwEdition commerce
Magento ≫ Magento Version 2.3.7 Update - SwEdition open_source
Magento ≫ Magento Version 2.4.2 Update - SwEdition commerce
Magento ≫ Magento Version 2.4.2 Update - SwEdition open_source
Magento ≫ Magento Version 2.4.2 Update p1 SwEdition commerce
Magento ≫ Magento Version 2.4.2 Update p1 SwEdition open_source
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.95% 0.776
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Adobe 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://helpx.adobe.com/security/products/magento/apsb21-64.html
Vendor Advisory