Description
A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited at the time of editing or configuration.
Remediation
References
Related Vulnerabilities
Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2021-28683)
WordPress Plugin Drag and Drop Multiple File Upload-Contact Form 7 Security Bypass (1.3.6.4)
Joomla Other Vulnerability (CVE-2006-4474)
Dot CMS Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-11466)
Jenkins Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5323)