VYPR
Critical severityNVD Advisory· Published Sep 1, 2021· Updated Sep 16, 2024

Magento Commerce XML Injection Vulnerability Could Lead To Remote Code Execution

CVE-2021-36028

Description

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability when saving a configurable product. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Magento Commerce versions 2.4.2, 2.4.2-p1, and 2.3.7 are vulnerable to XML Injection via configurable product saving, allowing admin-level remote code execution.

Vulnerability

Magento Commerce versions 2.4.2, 2.4.2-p1, and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the configurable product saving functionality. An attacker with admin privileges can inject malicious XML to trigger a specially crafted script. [1]

Exploitation

The attacker must have admin privileges on the Magento Commerce instance. The exploitation involves saving a configurable product with a specially crafted payload that exploits the XML Injection. The exact sequence of steps is not disclosed in the available references. [1]

Impact

Successful exploitation allows the attacker to achieve remote code execution with admin privileges, leading to full compromise of the application's confidentiality, integrity, and availability. [1]

Mitigation

No specific patch version or workaround is provided in the available references. Users should monitor Adobe security advisories for updates and consider upgrading to a patched version if available. [1]

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
magento/project-community-editionPackagist
<= 2.0.2
magento/community-editionPackagist
< 2.3.7-p12.3.7-p1
magento/community-editionPackagist
>= 2.4.2-p1, < 2.4.2-p22.4.2-p2

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.