Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special Elements Used In A Command via the Data collection endpoint. An attacker with admin privileges can upload a specially crafted file to achieve remote code execution.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HAdobe Commerce
APPAdobe2.4.22.3.0 – 2.3.72.4.0 – 2.4.2Adobe Magento Open Source
APPAdobe2.4.22.3.0 – 2.3.72.4.0 – 2.4.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCECommand Injection
Related vulnerabilities
CVE-2022-24093CRITICAL9.1PL ✓same product
Adobe Commerce / Magento — RCE przez improper input validation
CVE-2022-35698CRITICAL10.0PL ✓same product
Stored XSS z możliwością RCE w Adobe Commerce i Magento Open Source
CVE-2021-36029CRITICAL9.1PL ✓same product
RCE przez błąd autoryzacji w Adobe Magento Commerce
CVE-2021-36025CRITICAL9.1PL ✓same product
RCE w Adobe Magento/Commerce — improper input validation przy zapisie danych klienta
CVE-2021-36022CRITICAL9.1PL ✓same product
XML Injection w Magento Commerce — RCE przez Widgets Update Layout