Back

CRITICAL

Magento Commerce Widgets Module XML Injection Vulnerability Could Lead To Remote Code Execution

Published Sep 1, 2021

Description

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Sep 1, 2021
Updated Sep 16, 2024
Reserved Jun 30, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-P746-QW73-QMMX