Description
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
Remediation
References
Related Vulnerabilities
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17304)
Python Missing Initialization of Resource Vulnerability (CVE-2018-14647)
Drupal Core 8.6.x Directory Traversal (8.6.0 - 8.6.15)
PleskWin Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4878)