GHSA-4g27-q2w9-m8m8
Dashboard / Vulnerabilities / GHSA-4g27-q2w9-m8m8
GHSA-4g27-q2w9-m8m8
Summary: Magento affected by remote code execution vulnerability in the CMS page scheduled update feature
Details: Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper input validation vulnerability within the CMS page scheduled update feature. An authenticated attacker with administrative privilege could leverage this vulnerability to achieve remote code execution on the system.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-36021, https://github.com/magento/magento2, https://helpx.adobe.com/security/products/magento/apsb21-64.html
Affected packages
Package
Name: magento/project-community-edition
Purl: pkg:composer/magento/project-community-edition
Affected ranges
Type: ECOSYSTEM
Events:
