Description
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error vulnerability. Successful exploitation could lead to privilege escalation.
Remediation
References
Related Vulnerabilities
WordPress Plugin Like Button Rating-LikeBtn Server-Side Request Forgery (2.6.31)
WordPress Plugin MC4WP:Mailchimp for WordPress Cross-Site Scripting (4.0.10)
phpMyAdmin Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-3055)
Oracle Database Server CVE-2009-0972 Vulnerability (CVE-2009-0972)