Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HMagento
APPMagento2.3.62.4.02.4.1< 2.3.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
Related vulnerabilities
CVE-2021-36023CRITICAL9.1PL ✓same product
XML Injection w Magento Commerce umożliwia RCE przez panel admina
CVE-2021-21016CRITICAL9.1PL ✓same product
Command Injection w Magento WebAPI umożliwiający RCE
CVE-2021-21019CRITICAL9.1PL ✓same product
XML Injection w module Widgets Magento umożliwiający RCE
CVE-2021-21018CRITICAL9.1PL ✓same product
Magento — OS command injection w module scheduled operations (RCE)
CVE-2021-21024CRITICAL9.1PL ✓same product
Blind SQL Injection w module Search platformy Magento