Magento versions 2.4.2 (and previous versions), 2.4.2-p1 (and previous versions) and 2.3.7 (and previous versions) are affected by an Improper input validation vulnerability within the CMS page scheduled update feature. An authenticated attacker with administrative privilege could leverage this vulnerability to achieve remote code execution on the system.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
magento magento |
||
magento magento 2.3.7 |
||
magento magento 2.4.2 |