Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within Magento's Media Gallery Upload workflow. By storing a specially crafted file in the website gallery, an authenticated attacker with administrative privilege can gain access to delete the .htaccess file. This could result in the attacker achieving remote code execution.
References
Link | Resource |
---|---|
https://helpx.adobe.com/security/products/magento/apsb21-64.html | Vendor Advisory |
https://helpx.adobe.com/security/products/magento/apsb21-64.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://helpx.adobe.com/security/products/magento/apsb21-64.html - Vendor Advisory |
11 Sep 2023, 19:05
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://helpx.adobe.com/security/products/magento/apsb21-64.html - Vendor Advisory | |
CPE | cpe:2.3:a:magento:magento:2.3.7:-:*:*:commerce:*:*:* cpe:2.3:a:magento:magento:2.4.2:p1:*:*:open_source:*:*:* cpe:2.3:a:magento:magento:2.4.2:-:*:*:open_source:*:*:* cpe:2.3:a:magento:magento:2.4.2:p1:*:*:commerce:*:*:* cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* cpe:2.3:a:magento:magento:2.3.7:-:*:*:open_source:*:*:* cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* cpe:2.3:a:magento:magento:2.4.2:-:*:*:commerce:*:*:* |
|
First Time |
Magento
Magento magento |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
06 Sep 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-06 14:15
Updated : 2024-11-21 06:12
NVD link : CVE-2021-36036
Mitre link : CVE-2021-36036
CVE.ORG link : CVE-2021-36036
JSON object : View
Products Affected
magento
- magento
CWE
CWE-284
Improper Access Control