Description
In Magento prior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit product attributes can execute arbitrary code through crafted layout updates.
Remediation
References
Related Vulnerabilities
MySQL CVE-2024-21231 Vulnerability (CVE-2024-21231)
SharePoint Deserialization of Untrusted Data Vulnerability (CVE-2025-30384)
Django URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-14574)
IBM WebSEAL Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2020-4699)