VYPR
Critical severity9.1NVD Advisory· Published Sep 1, 2021· Updated Jun 17, 2026

CVE-2021-36035

CVE-2021-36035

Description

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges could make a crafted request to the Adobe Stock API to achieve remote code execution.

Affected products

6
  • cpe:2.3:a:adobe:adobe_commerce:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:adobe_commerce:*:*:*:*:*:*:*:*range: >=2.3.0,<=2.3.7
    • cpe:2.3:a:adobe:adobe_commerce:2.4.2:p1:*:*:*:*:*:*
  • cpe:2.3:a:adobe:magento_open_source:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:magento_open_source:*:*:*:*:*:*:*:*range: >=2.3.0,<=2.3.7
    • cpe:2.3:a:adobe:magento_open_source:2.4.2:p1:*:*:*:*:*:*
  • Adobe Inc./Magento Commercellm-fuzzy2 versions
    <=2.4.2, <=2.4.2-p1, <=2.3.7+ 1 more
    • (no CPE)range: <=2.4.2, <=2.4.2-p1, <=2.3.7
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.