Vulnerability Details CVE-2021-36029
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.05
EPSS Ranking 89.1%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 6.5
Products affected by CVE-2021-36029
-
cpe:2.3:a:adobe:adobe_commerce:*
-
cpe:2.3:a:adobe:adobe_commerce:2.4.2
-
cpe:2.3:a:adobe:magento_open_source:2.3.7
-
cpe:2.3:a:adobe:magento_open_source:2.4.0
-
cpe:2.3:a:adobe:magento_open_source:2.4.1
-
cpe:2.3:a:adobe:magento_open_source:2.4.2