Description
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.
Remediation
References
Related Vulnerabilities
Skipper Server-Side Request Forgery (SSRF) Vulnerability (CVE-2022-38580)
Beego Framework CVE-2021-30080 Vulnerability (CVE-2021-30080)
WordPress Plugin A.M.Y. Cross-Site Scripting (1.3.3)
Ruby Improper Restriction of XML External Entity Reference Vulnerability (CVE-2021-28965)
MediaWiki Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2022-41766)