9.1

CVE-2021-36023

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.

Data is provided by the National Vulnerability Database (NVD)
MagentoMagento SwEditioncommerce Version < 2.3.7
MagentoMagento SwEditionopen_source Version < 2.3.7
MagentoMagento SwEditioncommerce Version >= 2.4.0 < 2.4.2
MagentoMagento SwEditionopen_source Version >= 2.4.0 < 2.4.2
MagentoMagento Version2.3.7 Update- SwEditioncommerce
MagentoMagento Version2.3.7 Update- SwEditionopen_source
MagentoMagento Version2.4.2 Update- SwEditioncommerce
MagentoMagento Version2.4.2 Update- SwEditionopen_source
MagentoMagento Version2.4.2 Updatep1 SwEditioncommerce
MagentoMagento Version2.4.2 Updatep1 SwEditionopen_source
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 9.65% 0.926
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
psirt@adobe.com 9.1 2.3 6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.