VYPR
Critical severity9.1NVD Advisory· Published Feb 11, 2021· Updated Jun 17, 2026

CVE-2021-21014

CVE-2021-21014

Description

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
magento/community-editionPackagist
< 2.3.6-p12.3.6-p1
magento/community-editionPackagist
>= 2.4.0, < 2.4.22.4.2
magento/project-community-editionPackagist
<= 2.0.2

Affected products

14
  • Magento/Magento10 versions
    cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*+ 9 more
    • cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*range: <2.3.6
    • cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*range: <2.3.6
    • cpe:2.3:a:magento:magento:2.3.6:-:*:*:commerce:*:*:*
    • cpe:2.3:a:magento:magento:2.3.6:-:*:*:open_source:*:*:*
    • cpe:2.3:a:magento:magento:2.4.0:-:*:*:commerce:*:*:*
    • cpe:2.3:a:magento:magento:2.4.0:-:*:*:open_source:*:*:*
    • cpe:2.3:a:magento:magento:2.4.0:p1:*:*:commerce:*:*:*
    • cpe:2.3:a:magento:magento:2.4.0:p1:*:*:open_source:*:*:*
    • cpe:2.3:a:magento:magento:2.4.1:-:*:*:commerce:*:*:*
    • cpe:2.3:a:magento:magento:2.4.1:-:*:*:open_source:*:*:*
  • osv-coords3 versions
    < 2.3.6+ 2 more
    • (no CPE)range: < 2.3.6
    • (no CPE)range: < 2.3.6-p1
    • (no CPE)range: <= 2.0.2
  • Range: unspecified

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.