Critical severity9.1NVD Advisory· Published Sep 1, 2021· Updated Jun 17, 2026
CVE-2021-36035
CVE-2021-36035
Description
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges could make a crafted request to the Adobe Stock API to achieve remote code execution.
Affected products
6cpe:2.3:a:adobe:adobe_commerce:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:adobe:adobe_commerce:*:*:*:*:*:*:*:*range: >=2.3.0,<=2.3.7
- cpe:2.3:a:adobe:adobe_commerce:2.4.2:p1:*:*:*:*:*:*
cpe:2.3:a:adobe:magento_open_source:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:adobe:magento_open_source:*:*:*:*:*:*:*:*range: >=2.3.0,<=2.3.7
- cpe:2.3:a:adobe:magento_open_source:2.4.2:p1:*:*:*:*:*:*
<=2.4.2, <=2.4.2-p1, <=2.3.7+ 1 more
- (no CPE)range: <=2.4.2, <=2.4.2-p1, <=2.3.7
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
1- helpx.adobe.com/security/products/magento/apsb21-64.htmlnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.