Description
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).
Remediation
References
Related Vulnerabilities
WordPress Plugin Inline Related Posts Multiple Cross-Site Scripting Vulnerabilities (3.0.4)
MySQL Resource Management Errors Vulnerability (CVE-2010-3837)
WordPress Plugin Relevanssi-A Better Search 'Seach Query' Field HTML Injection (2.7.2)
WordPress Plugin Visual CSS Style Editor Cross-Site Request Forgery (7.2.0)