Description
An arbitrary file deletion vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated users can manipulate the design layout update feature.
Remediation
References
Related Vulnerabilities
MySQL CVE-2017-3329 Vulnerability (CVE-2017-3329)
Moodle Other Vulnerability (CVE-2019-10188)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1428)
Joomla! Core 3.x.x Cross-Site Request Forgery (3.0.0 - 3.9.26)
WordPress Plugin WP e-Commerce-Store Toolkit Privilege Escalation (2.0.1)