Description
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within Magento's Media Gallery Upload workflow. By storing a specially crafted file in the website gallery, an authenticated attacker with administrative privilege can gain access to delete the .htaccess file. This could result in the attacker achieving remote code execution.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Limit Posts Automatically Cross-Site Request Forgery (0.7)
WordPress Plugin Timetable and Event Schedule by MotoPress Cross-Site Scripting (2.3.18)
MySQL Use After Free Vulnerability (CVE-2019-7317)
WordPress Plugin Elementor Website Builder Cross-Site Scripting (2.9.8)
WordPress Plugin Carousel slideshow 'upload.php' Arbitrary File Upload (3.9)