Description
A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3. An authenticated admin user with privileges to access product attributes can leverage layout updates to trigger remote code execution.
Remediation
References
Related Vulnerabilities
Moodle Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-25978)
WordPress Plugin Note Press SQL Injection (0.1.1)
WordPress Plugin WordPress Download Manager Cross-Site Request Forgery (3.2.12)
Ruby on Rails Improper Input Validation Vulnerability (CVE-2014-0082)
WordPress Plugin Master Slider-WordPress Responsive Touch Slider Unspecified Vulnerability (2.18.2)