Magento Commerce XML Injection Vulnerability Could Lead To Remote Code Execution
Description
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability when saving a configurable product. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Magento Commerce versions 2.4.2, 2.4.2-p1, and 2.3.7 are vulnerable to XML Injection via configurable product saving, allowing admin-level remote code execution.
Vulnerability
Magento Commerce versions 2.4.2, 2.4.2-p1, and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the configurable product saving functionality. An attacker with admin privileges can inject malicious XML to trigger a specially crafted script. [1]
Exploitation
The attacker must have admin privileges on the Magento Commerce instance. The exploitation involves saving a configurable product with a specially crafted payload that exploits the XML Injection. The exact sequence of steps is not disclosed in the available references. [1]
Impact
Successful exploitation allows the attacker to achieve remote code execution with admin privileges, leading to full compromise of the application's confidentiality, integrity, and availability. [1]
Mitigation
No specific patch version or workaround is provided in the available references. Users should monitor Adobe security advisories for updates and consider upgrading to a patched version if available. [1]
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
magento/project-community-editionPackagist | <= 2.0.2 | — |
magento/community-editionPackagist | < 2.3.7-p1 | 2.3.7-p1 |
magento/community-editionPackagist | >= 2.4.2-p1, < 2.4.2-p2 | 2.4.2-p2 |
Affected products
4- Range: <=2.4.2-p1
- ghsa-coords2 versions
< 2.3.7-p1+ 1 more
- (no CPE)range: < 2.3.7-p1
- (no CPE)range: <= 2.0.2
- Adobe/Magento Commercev5Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-5pjj-7fq8-9gpfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-36028ghsaADVISORY
- helpx.adobe.com/security/products/magento/apsb21-64.htmlghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.