Description
Insufficient enforcement of user access controls in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could enable a low-privileged user to make unauthorized environment configuration changes.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2020-2803 Vulnerability (CVE-2020-2803)
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-3628)
WordPress Plugin Team Members Unspecified Vulnerability (2.1.2)
Oracle Application Server Other Vulnerability (CVE-2002-1631)
WordPress Plugin WP e-Commerce-Store Exporter Privilege Escalation (1.6.6)