Description
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
Remediation
References
Related Vulnerabilities
WordPress Plugin iThemes Security (formerly Better WP Security) Security Bypass (5.3.0)
WordPress Plugin SVG Support Cross-Site Scripting (2.5.1)
PHP Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2011-0441)
TYPO3 Improper Input Validation Vulnerability (CVE-2011-4904)