Description
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with system data manipulation privileges can execute aribitrary code through arbitrary file deletion and OS command injection.
Remediation
References
Related Vulnerabilities
Lighttpd Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-1111)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-3230)
WordPress Plugin WP SEO Redirect 301 Cross-Site Request Forgery (2.3.1)
Sqlite Out-of-bounds Read Vulnerability (CVE-2019-9936)
SharePoint Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-1443)