Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-36036


Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within Magento's Media Gallery Upload workflow. By storing a specially crafted file in the website gallery, an authenticated attacker with administrative privilege can gain access to delete the .htaccess file. This could result in the attacker achieving remote code execution.


Published

2023-09-06T14:15:09.110

Last Modified

2024-11-21T06:12:59.950

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Primary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application magento magento < 2.3.7 Yes
Application magento magento < 2.3.7 Yes
Application magento magento < 2.4.2 Yes
Application magento magento < 2.4.2 Yes
Application magento magento 2.3.7 Yes
Application magento magento 2.3.7 Yes
Application magento magento 2.4.2 Yes
Application magento magento 2.4.2 Yes
Application magento magento 2.4.2 Yes
Application magento magento 2.4.2 Yes

References