Description
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.
Remediation
References
Related Vulnerabilities
TYPO3 Deserialization of Untrusted Data Vulnerability (CVE-2020-11067)
Python Other Vulnerability (CVE-2006-4980)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-19968)
Oracle Application Server CVE-2006-0290 Vulnerability (CVE-2006-0290)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-3394)