CVE-2021-28584
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
28/06/2021
Last modified:
06/07/2021
Description
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Path Traversal vulnerability when creating a store with child theme.Successful exploitation could lead to arbitrary file system write by an authenticated attacker. Access to the admin console is required for successful exploitation.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:* | 2.3.6 (excluding) | |
| cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:* | 2.3.6 (excluding) | |
| cpe:2.3:a:magento:magento:2.3.6:-:*:*:commerce:*:*:* | ||
| cpe:2.3:a:magento:magento:2.3.6:-:*:*:open_source:*:*:* | ||
| cpe:2.3:a:magento:magento:2.3.6:p1:*:*:commerce:*:*:* | ||
| cpe:2.3:a:magento:magento:2.3.6:p1:*:*:open_source:*:*:* | ||
| cpe:2.3:a:magento:magento:2.4.1:-:*:*:commerce:*:*:* | ||
| cpe:2.3:a:magento:magento:2.4.1:-:*:*:open_source:*:*:* | ||
| cpe:2.3:a:magento:magento:2.4.1:p1:*:*:commerce:*:*:* | ||
| cpe:2.3:a:magento:magento:2.4.1:p1:*:*:open_source:*:*:* | ||
| cpe:2.3:a:magento:magento:2.4.2:*:*:*:commerce:*:*:* | ||
| cpe:2.3:a:magento:magento:2.4.2:*:*:*:open_source:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



