Description
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to arbitrary code execution.
Remediation
References
Related Vulnerabilities
Perl Out-of-bounds Read Vulnerability (CVE-2018-18313)
WordPress Plugin weForms-Easy Drag & Drop Contact Form Builder For WordPress CSV Injection (1.4.7)
Python Improper Restriction of XML External Entity Reference Vulnerability (CVE-2017-9233)
Magento Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-8156)