Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Violation of Secure Design Principles vulnerability in RMA PDF filename formats. Successful exploitation could allow an attacker to get unauthorized access to restricted resources.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NMagento
APPMagento2.3.62.4.12.4.2< 2.3.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2021-36023CRITICAL9.1PL ✓same product
XML Injection w Magento Commerce umożliwia RCE przez panel admina
CVE-2021-21014CRITICAL9.1PL ✓same product
Magento: ominięcie ograniczeń przesyłania plików prowadzące do RCE
CVE-2021-21018CRITICAL9.1PL ✓same product
Magento — OS command injection w module scheduled operations (RCE)
CVE-2021-21016CRITICAL9.1PL ✓same product
Command Injection w Magento WebAPI umożliwiający RCE
CVE-2021-21019CRITICAL9.1PL ✓same product
XML Injection w module Widgets Magento umożliwiający RCE