Description
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundled dotmailer extension. An attacker with admin privileges could abuse this to achieve remote code execution should Redis be enabled.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-22676 | Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundled dotmailer extension. An attacker with admin privileges could abuse this to achieve remote code execution should Redis be enabled. |
Github GHSA |
GHSA-36xq-7w8w-xp68 | Magento affected by a blind SSRF vulnerability in the bundled dotmailer extension |
References
History
No history.
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-09-16T20:36:46.572Z
Reserved: 2021-06-30T00:00:00.000Z
Link: CVE-2021-36043
No data.
Status : Modified
Published: 2021-09-01T15:15:10.293
Modified: 2024-11-21T06:13:00.833
Link: CVE-2021-36043
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA