Description
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to arbitrary code execution.
Remediation
References
Related Vulnerabilities
Zope Web Application Server CVE-2011-3587 Vulnerability (CVE-2011-3587)
WordPress Plugin Shortlinks by Pretty Links-Best WordPress Link Tracking SQL Injection (1.6.7)
WordPress Plugin Wechat Reward Cross-Site Request Forgery (1.7)
WordPress Plugin BuddyPress Global Search Cross-Site Scripting (1.1.0)
Liferay Portal Improper Restriction of XML External Entity Reference Vulnerability (CVE-2024-25606)