Description
A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can bypass the email confirmation mechanism via GET request that captures relevant account data obtained from the POST response related to new user creation.
Remediation
References
Related Vulnerabilities
WordPress Plugin SP Project & Document Manager Arbitrary File Upload (4.21)
WordPress Plugin Simple Membership Cross-Site Scripting (3.5.6)
Oracle JRE CVE-2022-21619 Vulnerability (CVE-2022-21619)
WordPress Plugin Quote-O-Matic SQL Injection (1.0.5)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-5020)