Description
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to manipulate CMS section of the website can trigger remote code execution via custom layout update.
Remediation
References
Related Vulnerabilities
WordPress Plugin ImageInject Multiple Vulnerabilities (1.15)
WordPress Plugin HandL UTM Grabber Security Bypass (2.6.4)
WordPress Plugin Floating Social Bar Cross-Site Scripting (1.1.5)
WordPress Plugin Customize Feeds for Twitter Cross-Site Request Forgery (1.8.8)
Joomla Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-11322)