ZeroHour

CVE-2021-36029

CVSS 3.1
7.2 high
EPSS
2%p84
Published
()
Modified
Description

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.

Vendors
adobe
Products
adobe commerce, magento open source
Ecosystems
E-commerce
Weakness
CWE-285
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news