CVE-2021-36020
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the 'City' field. An unauthenticated attacker can trigger a specially crafted script to achieve remote code execution.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- EPSS probability
- 31.07%
- CWE
- CWE-91
- Published
- 2021-09-01
- Last modified
- 2026-03-13
Affected products
- Adobe Magento Commerce
Weakness type
Related vulnerabilities
- CVE-2023-46214 — Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing
- CVE-2022-34253 — Adobe Commerce XML Injection Arbitrary code execution
- CVE-2021-36033 — Magento Commerce Widgets Module XML Injection Vulnerability Could Lead To Remote Code Execution
- CVE-2021-36028 — Magento Commerce XML Injection Vulnerability Could Lead To Remote Code Execution
- CVE-2020-8479 — ABB Central Licensing System - XML External Entity Injection
- CVE-2021-21025 — Magento Commerce XML Injection Could Lead To Arbitrary Code Execution
- CVE-2021-21019 — Magento Commerce XML Injection Could Lead To Remote Code Execution
- CVE-2021-39181 — Unsafe Deserialization of User Data Using XStream