Description
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.
Remediation
References
Related Vulnerabilities
WordPress Plugin Brandfolder-Digital Asset Management Simplified Local/Remote File Inclusion (3.0)
Roundcube Unspesificed Vulnerability (CVE-2019-15237)
WebLogic CVE-2023-21956 Vulnerability (CVE-2023-21956)
Lighttpd Other Vulnerability (CVE-2006-0760)
phpMyFAQ Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-15731)